Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Ivanti: ‘Critical’ Mobile Management Vulnerabilities Seeing Exploitation

CRN by CRN
January 30, 2026
Home News
Share on FacebookShare on Twitter


A pair of flaws affecting Ivanti’s Endpoint Manager Mobile have been exploited in attacks impacting a ‘very limited’ number of customers, the company says.

A pair of critical-severity vulnerabilities affecting an Ivanti mobile management tool have been exploited in cyberattacks, according to the company.

The flaws—tracked at CVE-2026-1281 and CVE-2026-1340—affect Ivanti’s Endpoint Manager Mobile and have been exploited in attacks impacting a “very limited” number of customers, Ivanti said in an advisory Thursday.

[Related: 10 Major Cyberattacks And Data Breaches In 2025]

Patches are available to address the vulnerabilities, Ivanti said.

“No downtime is required to apply this patch, and we are not aware of any feature functionality impact with this patch,” the company said.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released its own advisory Thursday confirming that at least one of the vulnerabilities (CVE-2026-1281) has been exploited by threat actors.

“This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise,” CISA said in the advisory.

Both vulnerabilities have a “critical” severity score of 9.8 out of 10.0.

In its advisory, Ivanti said the code injection vulnerabilities can be exploited to enable remote execution of code without authentication.

“We are aware of a very limited number of customers who have been exploited at the time of disclosure,” the company said in its advisory.

CRN has reached out to Ivanti for further comment.

CISA ordered federal agencies to implement patches for the Ivanti vulnerabilities by Feb. 1.

While the order only applies to Federal Civilian Executive Branch agencies, CISA “strongly urges” all impacted organizations to prioritize remediation of exploited vulnerabilities such as these, the agency said.



Source link

Tags: CyberattacksCybersecurityVulnerabilities
CRN

CRN

Next Post
Everything you need to know about Kevin Warsh, Trump’s pick to lead the Federal Reserve

Everything you need to know about Kevin Warsh, Trump's pick to lead the Federal Reserve

Recommended.

The Coolest Data Warehouse And Data Lake System Companies Of The 2025 Big Data 100

The Coolest Data Warehouse And Data Lake System Companies Of The 2025 Big Data 100

April 22, 2025
Deutsche Bank says the market sell-off has another 6% to go as consumer and corporate confidence dives

Deutsche Bank says the market sell-off has another 6% to go as consumer and corporate confidence dives

March 17, 2025

Trending.

Spirit of openness helps banks get serious about stopping scams | Computer Weekly

Spirit of openness helps banks get serious about stopping scams | Computer Weekly

April 10, 2025
Microsoft Q3 Earnings Preview: What To Watch On Azure, Copilot, OpenAI

Microsoft Q3 Earnings Preview: What To Watch On Azure, Copilot, OpenAI

April 29, 2026
Weibo Publishes 2025 Environmental, Social and Governance Report

Weibo Publishes 2025 Environmental, Social and Governance Report

April 28, 2026
It Takes 2 Minutes to Hack the EU’s New Age-Verification App

It Takes 2 Minutes to Hack the EU’s New Age-Verification App

April 18, 2026
Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

Chunghwa Telecom 2025 Form 20-F filed with the U.S. SEC

April 15, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio