Summary
Ivanti Endpoint Manager Mobile (EPMM) has a code injection flaw in the Android File Transfer handling path. An unauthenticated attacker can send crafted HTTP GET requests to the /mifs/c/aftstore/fob/ endpoint, which feeds legacy Apache RewriteMap Bash helpers that can evaluate attacker-controlled values and execute commands. Successful exploitation can lead to full appliance compromise, web shells, and access to managed-device and admin data.
Why Emergency Fix?
6/6Exploitation Details
Execute arbitrary OS commands on the EPMM appliance, deploy web shells, and access managed-device and admin data.
Full System CompromiseAffected Software
| Product | Affected Versions |
|---|---|
| Ivanti Endpoint Manager Mobile (EPMM) | 12.5.1.0 and prior; 12.6.1.0 and prior; 12.7.0.0 and prior |
On-premises mobile device management platform used by enterprises to enroll, manage, secure, and distribute apps and policies to mobile devices.
Affected ComponentAndroid File Transfer Configuration endpoint and legacy Apache RewriteMap Bash helper script (map-aft-store-url) behind the /mifs/c/aftstore/fob/ path.
Android File Transfer Configuration endpoint and legacy Apache RewriteMap Bash helper script (map-aft-store-url) behind the /mifs/c/aftstore/fob/ path.
Affected Endpoints(1)/mifs/c/aftstore/fob/
Not available
Apply the version-specific Ivanti RPM security update: use 12.x.0.x for 12.5.0.x/12.6.0.x/12.7.0.x branches and 12.x.1.x for 12.5.1.0/12.6.1.0 branches; reapply after any version upgrade because the RPM does not persist.
Apply the version-specific Ivanti RPM security update: use 12.x.0.x for 12.5.0.x/12.6.0.x/12.7.0.x branches and 12.x.1.x for 12.5.1.0/12.6.1.0 branches; reapply after any version upgrade because the RPM does not persist.
Not available
Probability of exploitation in the next 30 days
Worse than 99% of all CVEs
No known threat actors
NVD Data
Description Summary
CVSS Base Score
CVSS Vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Software (CPE) (1)
- •cpe:2.3:a:ivanti:endpoint_manager_mobile:*:*:*:*:*:*:*:*
Sources
| Source | Article |
|---|---|
| www.ivanti.com | January 2026 EPMM Security Update |
| hub.ivanti.com | Security Advisory: Ivanti Endpoint Manager Mobile (EPMM) |
| labs.watchtowr.com | Someone Knows Bash Far Too Well, And We Love It (Ivanti EPMM Pre-Auth RCEs CVE-2026-1281 & CVE-2026-1340) |
| unit42.paloaltonetworks.com | Critical Vulnerabilities in Ivanti EPMM Exploited |
| www.cert.europa.eu | Security Advisory 2026-001: Critical vulnerabilities in Ivanti EPMM |
| www.tenable.com | CVE-2026-1281, CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Zero-Day Vulnerabilities Exploited |
Priority History
Initial analysis