PatchSiren cyber security CVE debrief
CVE-2026-1340 Ivanti CVE debrief
CVE-2026-1340 is a code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that CISA added to the Known Exploited Vulnerabilities catalog on 2026-04-08. The supplied CISA guidance emphasizes assessing exposure, checking internet-accessible affected products for signs of compromise, and applying vendor mitigations as soon as possible. If mitigations are unavailable, CISA advises discontinuing use of the product.
- Vendor
- Ivanti
- Product
- Endpoint Manager Mobile (EPMM)
- CVSS
- CRITICAL 9.8
- CISA KEV
- Listed
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-04-08
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-04-08
Who should care
Organizations running Ivanti Endpoint Manager Mobile (EPMM), especially internet-facing deployments; security operations teams; and administrators responsible for mobile device management infrastructure.
Technical summary
The supplied source corpus identifies CVE-2026-1340 as a code injection issue affecting Ivanti Endpoint Manager Mobile (EPMM). CISA listed it in the KEV catalog on 2026-04-08 with a mitigation due date of 2026-04-11. The source notes instruct affected operators to assess exposure, look for signs of potential compromise on all internet-accessible affected Ivanti products, and apply final vendor mitigations as soon as possible. No additional technical mechanics or CVSS score were provided in the corpus.
Defensive priority
Immediate
Recommended defensive actions
- Inventory all Ivanti Endpoint Manager Mobile (EPMM) deployments and determine whether any are internet accessible.
- Follow Ivanti's published mitigation and upgrade guidance for CVE-2026-1340 as soon as possible.
- Review exposed EPMM systems for signs of potential compromise.
- If mitigations are unavailable, discontinue use of the product until a safe remediation path exists.
- Apply applicable CISA BOD 22-01 guidance for cloud services where relevant.
- Track the CISA KEV due date of 2026-04-11 as the operational deadline for remediation.
Evidence notes
This debrief is based only on the supplied CISA KEV source item and the official CVE/NVD/CISA resource links. The source metadata explicitly identifies CVE-2026-1340 as an Ivanti Endpoint Manager Mobile (EPMM) code injection vulnerability, adds it to KEV on 2026-04-08, and sets a due date of 2026-04-11. The corpus does not include a CVSS score or deeper exploit mechanics. CISA's notes also reference vendor guidance, compromise checking for internet-accessible affected products, and final mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-1340 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-1340
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-1340 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1340
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.