CVE Tools
Back to feed
watchTowr Labs ·EN Vendor research

Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340)

By Piotr Bazydlo (@chudyPB)··8 min read

When Ivanti removed the embargoes from CVE-2026-1281 and CVE-2026-1340 - actively exploited pre-auth Remote Command Execution vulnerabilities in Ivanti’s Endpoint Manager Mobile (EPMM) solution - we sighed with relief.

Clearly, the universe had decided to continue mocking Secure-By-Design signers right on schedule - every January.…

Continue reading on watchTowr Labs