loader image
Ivanti EPMM: IT team inspects server hatch in minimalist room with drifting data ribbons, warning LEDs and web-like intrusion
Ivanti EPMM Under Single-IP RCE Siege

A critical remote code execution flaw, tracked as CVE-2026-1281, is affecting Ivanti Endpoint Manager Mobile (EPMM) and being heavily exploited, according to security data. GreyNoise reports that 83% of these attacks originate from one IP address, 193.24.123.42, registered to PROSPERO OOO, known for “bulletproof” hosting. This IP was notably absent from initial indicators of compromise shared among defenders. Two Ivanti EPMM vulnerabilities, including CVE-2026-1340, with a CVSS score of 9.8, enable attackers to execute unauthorized commands, prompting immediate concern. Following Ivanti’s advisory on January 29, CISA quickly recognized the severity and added it to their Known Exploited Vulnerabilities catalog. Attacks have reportedly breached Dutch agencies, accelerating before patches were deployed. Also linked are defensive gaps, with many IOCs missing the mark, risking incomplete threat mitigation. Comprehensive defense is crucial, especially since dormant “sleeper” webshells can compromise even patched systems. For more detailed insights, access the full article here:

Single IP Dominates Exploitation Campaign Attacking Ivanti EPMM with RCE Vulnerability

Write a Reply or Comment

Your email address will not be published. Required fields are marked *