CVE-2026-1340 — Ivanti Endpoint Manager Mobile (EPMM)
Ivanti Endpoint Manager Mobile contains a code injection vulnerability that can allow unauthenticated remote code execution.
Why it matters: A network-reachable RCE on a management surface is the kind of issue that can turn into immediate organizational compromise if exposed.
CVSS
9.8
Category
Code injection / RCE
Vendor
Ivanti
KEV added
2026-04-08