PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-1340 Ivanti CVE debrief

CVE-2026-1340 is a code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that CISA added to the Known Exploited Vulnerabilities catalog on 2026-04-08. The supplied CISA guidance emphasizes assessing exposure, checking internet-accessible affected products for signs of compromise, and applying vendor mitigations as soon as possible. If mitigations are unavailable, CISA advises discontinuing use of the product.

Vendor
Ivanti
Product
Endpoint Manager Mobile (EPMM)
CVSS
CRITICAL 9.8
CISA KEV
Listed
Original CVE published
2026-04-08
Original CVE updated
2026-04-08
Advisory published
2026-04-08
Advisory updated
2026-04-08

Who should care

Organizations running Ivanti Endpoint Manager Mobile (EPMM), especially internet-facing deployments; security operations teams; and administrators responsible for mobile device management infrastructure.

Technical summary

The supplied source corpus identifies CVE-2026-1340 as a code injection issue affecting Ivanti Endpoint Manager Mobile (EPMM). CISA listed it in the KEV catalog on 2026-04-08 with a mitigation due date of 2026-04-11. The source notes instruct affected operators to assess exposure, look for signs of potential compromise on all internet-accessible affected Ivanti products, and apply final vendor mitigations as soon as possible. No additional technical mechanics or CVSS score were provided in the corpus.

Defensive priority

Immediate

Recommended defensive actions

  • Inventory all Ivanti Endpoint Manager Mobile (EPMM) deployments and determine whether any are internet accessible.
  • Follow Ivanti's published mitigation and upgrade guidance for CVE-2026-1340 as soon as possible.
  • Review exposed EPMM systems for signs of potential compromise.
  • If mitigations are unavailable, discontinue use of the product until a safe remediation path exists.
  • Apply applicable CISA BOD 22-01 guidance for cloud services where relevant.
  • Track the CISA KEV due date of 2026-04-11 as the operational deadline for remediation.

Evidence notes

This debrief is based only on the supplied CISA KEV source item and the official CVE/NVD/CISA resource links. The source metadata explicitly identifies CVE-2026-1340 as an Ivanti Endpoint Manager Mobile (EPMM) code injection vulnerability, adds it to KEV on 2026-04-08, and sets a due date of 2026-04-11. The corpus does not include a CVSS score or deeper exploit mechanics. CISA's notes also reference vendor guidance, compromise checking for internet-accessible affected products, and final mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-1340 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-1340

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-1340 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-1340

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

  • CISA Known Exploited Vulnerabilities catalog

    Publisher, destination, and source semantics verified

    URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

    cisa_kev

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.