PT-2026-5357 · Ivanti · Ivanti Endpoint Manager Mobile

Published

2026-01-29

·

Updated

2026-07-08

·

CVE-2026-1281

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ivanti Endpoint Manager Mobile (affected versions not specified)
Description An unauthenticated remote code execution issue exists due to improper control of code generation, specifically a server-side template injection. Remote attackers can abuse a template rendering workflow exposed via the management interface to execute arbitrary OS-level commands in the context of the service. This can lead to full server compromise, takeover of the MDM infrastructure, and exposure of stored credentials or secrets. In a real-world incident, attackers linked to UNC5221 allegedly exploited this issue to steal sensitive data—including full names, phone numbers, email addresses, device identifiers, and geolocation—from the mobile phones of Belgian State Security Service employees.
Recommendations Apply the security updates for Ivanti Endpoint Manager Mobile as published in the official advisory channel. Restrict access to management ports (typically 443 and 8443) to VPN, jump hosts, and allowlisted IPs only. Disable non-essential template rendering features or endpoints as a temporary containment measure.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01061
BDU:2026-01123
CVE-2026-1281

Affected Products

Ivanti Endpoint Manager Mobile