INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Ivanti EPMM Zero-Day Exploit Frenzy

| 2026-02-17 20:35 CRITICAL HIGH
Executive Summary AI-generated
The threat landscape is rapidly evolving, with two critical zero-day vulnerabilities - CVE-2026-1281 and CVE-2026-1340 - being actively exploited in the wild. Ivanti Endpoint Manager Mobile (EPMM) is a highly targeted sector, with enterprise mobile fleets and corporate networks bearing the brunt of these attacks. The U.S. Cybersecurity and Infrastructure Security Agency has added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, emphasizing the need for swift action from organizations worldwide. Palo Alto Networks customers are advised to take immediate measures to protect themselves against these exploits, including implementing patches and referring to Ivanti's security advisory. The threat actors' accelerated operations highlight the importance of vigilance and proactive defense in maintaining a robust cybersecurity posture.
Technical Mitigations AI-generated
* Apply the latest version of Ivanti EPMM: Ensure that your enterprise mobile fleets and corporate networks use the most up-to-date RPM versions (e.g., RPM 12.x.0.x or RPM 12.x.1.x) to patch CVE-2026-1281 and CVE-2026-1340 vulnerabilities. * Implement a secure file system access mechanism: Use a secure file system access mechanism, such as encrypted storage or secure containerization (e.g., Docker), to protect mobile device management (MDM) infrastructure from unauthorized access. * Monitor for suspicious activity and implement incident response plans: Establish an incident response plan that includes monitoring for suspicious activity, such as unusual login attempts or changes in MDM configuration. Engage with a security expert or Unit 42 Incident Response team if you suspect a compromise. * Regularly update and patch software components: Regularly update and patch all software components, including Apache web servers, to ensure that known vulnerabilities are addressed before they can be exploited by attackers. * Use secure communication protocols (e.g., HTTPS): Ensure that mobile device management infrastructure is communicating securely over the internet using HTTPS. This will help prevent man-in-the-middle attacks and protect sensitive data in transit.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
SparkSpark CVE-2026-1281CVE-2026-1281 CVE-2026-1340CVE-2026-1340 CVE-2026-12821CVE-2026-12821
Target & Sectors
NORDICS NORDICS BENELUX BENELUX FIVE_EYES FIVE_EYES healthcarehealthcare defensedefense legallegal governmentgovernment manufacturingmanufacturing technologytechnology
Incident Timeline
Jan. 20
Threat actors exploited critical vulnerabilities in Ivanti EPMM.
infrastructure Ivanti
malware Spark
organisation Ivanti Bugs
organisation the European Commission
January 2026
The threat actors used a command to target vulnerable Ivanti EPMM servers by setting the st parameter in Apache RewriteMap configurations to the string "theValue".
organisation Ivanti
vulnerability CVE-2026-1281
vulnerability CVE-2026-1340
organisation CVE-2026
organisation Palo Alto Networks
organisation Gitee
organisation Cortex XDR
organisation XQL
organisation Nezha
organisation RPM 12.x.1.x
infrastructure 9.8
infrastructure Android
organisation the Ivanti Android File Transfer
organisation NCSC‑NL
organisation NGFW
data_breach 0 dataset
organisation Current Scope of the Exploitation Unit
organisation JSP
organisation the In-House Application Distribution
organisation theValue
organisation RCE
organisation POC
organisation EPMM Version
organisation Cyber Threat Alliance
organisation CTA
organisation Threat Prevention
organisation Cloud-Delivered Security Services
organisation DNS Security
organisation Expander
organisation Cortex XSIAM
organisation ASM
infrastructure 30 //Description
infrastructure 31 //Description
infrastructure 32 //Description
Jan. 29
Valtori exploited a vulnerability in Ivanti's Endpoint Manager Mobile (EPMM) solution to breach the company.
organisation Ivanti
organisation EPMM
organisation Endpoint
Jan. 30
ClickFix Attacks Abuses exploited critical vulnerabilities in Ivanti EPMM.
organisation ClickFix Attacks Abuses
Feb. 5
Valtori disclosed its incident on February 5.
organisation Valtori
Feb. 6
Threat actors exploited critical vulnerabilities in Ivanti EPMM and targeted the Dutch Data Protection Authority (AP) and Council for the Judiciary (Rvdr.
industry Government
infrastructure Ivanti
target_region Netherlands
attribution the Dutch Data Protection Authority
attribution AP
attribution the Council for the Judiciary (Rvdr
around Feb. 9
Shadowserver tracked another more voluminous wave of attempted attacks against Ivanti EPMM around February 9.
infrastructure Ivanti
tactic T1588.001 - Malware
industry Defense
organisation Shadowserver
Feb. 12
Ivanti's IP address is still active on Feb. 12, indicating potential ongoing exposure to the exploited vulnerabilities.
infrastructure Ivanti
Feb. 13
Threat actors exploited critical vulnerabilities in Ivanti EPMM to target the European Commission.
industry Government
infrastructure Ivanti
target_region Netherlands
2026-02-17
Threat actors are exploiting critical vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) to target enterprise mobile fleets and corporate networks.
infrastructure Ivanti
organisation Ivanti Endpoint
organisation EPMM
organisation Scam Abuses Gemini Chatbots
organisation IP
organisation CVE-2026
organisation the Common Vulnerability Scoring System
organisation CVSS
organisation MDM
organisation Cortex Xpanse
organisation POC
organisation SonicWall
organisation WatchGuard
victims 40,000 client base
Feb. 23, 2026
Threat actors exploited critical vulnerabilities in Ivanti EPMM.
observable 403.jsp
observable 401.jsp
observable 1.jsp
observable cssaaa.css
observable login.css
observable test.css
observable poc.css
Tactical Metrics
Metrics
infrastructure
​Ivanti
Affected Product
Metrics
infrastructure
​9.8
Software Version
Metrics
infrastructure
​Android
Affected Product
Metrics
data_breach
0
Dataset ^(?:[^P]*P)+Roduct=(?:[^,]+),([^:]+
Metrics
infrastructure
30
//Description
Metrics
infrastructure
31
//Description
Metrics
infrastructure
32
//Description
Metrics
victims
40,000
Client Base
Intelligence Sources