DNA View

⚠️ CISA Known Exploited Vulnerability

Active Threat

This vulnerability is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. Active exploitation has been observed in the wild. This poses significant risk to federal enterprises and should be prioritized for immediate patching.

CVE-2026-1281

Critical CISA KEV
Low Medium High Critical
9.8
CVSS Score
Published: Jan 29, 2026
Last Modified: Jan 30, 2026

Vulnerability Description

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
H
Integrity
H
Availability
H

Known Affected Software

65 configuration(s) from 1 vendor(s)

endpoint_manager_mobile
Version:
12.0.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.0.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.4.0.4
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.4.0.4:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.5.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.5.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.9.0.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.9.0.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.8.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.8.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.7.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.7.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.4.0.2
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.4.0.2:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.0.0.4
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.0.0.4:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.9.1.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.9.1.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.11.0.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.11.0.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.7.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.7.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.12.0.3
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.12.0.3:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.4.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.4.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.12.0.5
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.12.0.5:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.8.1.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.8.1.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.12.0.2
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.12.0.2:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.10.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.10.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.2.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.2.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.6.1.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.6.1.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.5.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.5.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.6.0.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.6.0.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.5.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.5.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.1.0.5
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.1.0.5:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.9.1.2
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.9.1.2:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.6.0.01
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.6.0.01:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.10.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.10.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.0.0.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.0.0.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.11.0.2
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.11.0.2:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.5.1.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.5.1.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.9.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.9.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.11.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.11.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.4.0.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.4.0.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.11.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.11.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.0.0.3
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.0.0.3:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.1.0.3
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.1.0.3:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.3.0.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.3.0.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.1.0.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.1.0.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.8.1.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.8.1.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.10.0.4
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.10.0.4:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.1.0.4
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.1.0.4:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.4.0.3
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.4.0.3:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.0.0.2
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.0.0.2:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.7.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.7.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.3.0.2
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.3.0.2:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.6.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.6.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.4.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.4.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.1.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.1.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.3.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.3.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.10.0.2
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.10.0.2:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.4.1.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.4.1.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.6.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.6.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.10.0.3
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.10.0.3:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.9.1.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.9.1.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.8.1.2
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.8.1.2:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.4.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.4.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.1.0.2
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.1.0.2:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.8.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.8.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.12.0.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.12.0.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.2.0.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.2.0.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.3.0.3
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.3.0.3:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.6.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.6.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.10.0.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.10.0.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.9.0
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.9.0:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
11.12.0.1
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:11.12.0.1:*:*:*:*:*:*:*
endpoint_manager_mobile
Version:
12.0.0.5
CPE:
cpe:2.3:a:ivanti:endpoint_manager_mobile:12.0.0.5:*:*:*:*:*:*:*
This vulnerability affects 65 software configuration(s). Ensure you patch all affected systems.

Severity Details

9.8
out of 10.0
Critical

CISA KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog

Weakness Type (CWE)

CWE-94 Top 25 #7

Improper Control of Generation of Code ('Code Injection')

Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Exploit Likelihood
Medium
Typical Severity
High
OWASP Top 10
A03:2021-Injection
Abstraction Level
Base

Key Information

Published Date
January 29, 2026

Related News Articles

Latest news and updates about CVE-2026-1281