CVE-2026-1340
-
Ivanti EPMM zero-days exploited in breach affecting Dutch data protection authority
A letter to the Dutch parliament said attackers exploited Ivanti EPMM vulnerabilities on 29 January, causing a breach that affected employees at the Dutch Data Protection Authority and the Council for the Judiciary with contact details possibly exposed.
-
European Commission discloses breach of mobile device management platform
The European Commission detected a cyber-attack on its mobile device management system on January 30 that may have exposed staff names and mobile numbers. The system was cleaned within nine hours and investigations are under way.
-
Ivanti issues fixes for two critical EPMM code injection zero day flaws
Ivanti released updates for two critical EPMM code injection vulnerabilities that allow unauthenticated remote code execution. One was added to the CISA KEV catalog. Patches, detection steps and remediation guidance are published in the vendor advisory.



