At the beginning of 2026, the cybersecurity landscape was shaken by the discovery of two serious vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) software, a tool used by many companies to manage mobile devices. These security flaws, identified as CVE-2026-1281 and CVE-2026-1340, were actively exploited by hackers before they could be fixed, in what experts call “zero-day” attacks.
The vulnerabilities in question allow malicious actors to execute code on EPMM servers without authentication, thus gaining complete control over the affected systems. According to research conducted, between February 1 and 9, 2026, 417 attempts to exploit these vulnerabilities were observed, with an alarming statistic: 83% of these attacks can be attributed to a single threat actor operating from an IP address associated with PROSPERO OOO, a provider known for offering “bulletproof” hosting services often used for illicit activities. The attacks were carried out using automated tools that verify the success of the infiltration via DNS callbacks.
The potential impact of these vulnerabilities is significant, considering that globally between 1,300 and 1,600 EPMM servers are exposed on the internet. Ivanti has confirmed that some customers have been effectively compromised, while Shadowserver, a non-profit organization dedicated to cybersecurity, has identified 86 already compromised instances. Since EPMM manages corporate mobile devices, a breach can potentially expose sensitive data and provide an entry point into corporate networks.
To protect themselves, organizations using Ivanti EPMM should immediately verify if their systems are vulnerable or already compromised, apply the security patches released by Ivanti, and, if necessary, temporarily isolate EPMM servers from the internet. It is also advisable to carefully monitor system logs to identify signs of compromise and strengthen authentication for all administrative access.
- Key points to remember:
- A single threat actor is responsible for most (83%) of the attacks on Ivanti EPMM’s critical vulnerabilities.
- About 86 servers have been confirmed as compromised, but the number could grow considering that up to 1,600 instances are exposed on the internet.
- Immediate application of security patches and monitoring of systems are essential to mitigate this ongoing threat.
Sources:
BleepingComputer, The Hacker News, GreyNoise, CyberScoop, Indusface
Source: BleepingComputer