Ivanti EPMM ‘Sleeper Shells’ not so sleepy?

In late January 2026, an advisory covering two remote code execution vulnerabilities (CVE-2026-1281 & CVE-2026-1340) in Ivanti Endpoint Manager Mobile (EPMM) was published. Shortly after, reports (in example by tenable) mentioned publicly available proof-of-concept exploits. On February 9th 2026, Defused published a blog post describing a specific webshell being deployed on EPMM devices via this … Continue reading Ivanti EPMM ‘Sleeper Shells’ not so sleepy?