Active exploitation of vulnerabilities on Ivanti Endpoint Manager Mobile (EPMM)
Why this matters
The regulatory update describes active exploitation of vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), a mobile endpoint management solution. This poses a severe risk to managed devices and sensitive data, especially for financial firms that use EPMM. The update requires immediate action and reporting of the incident.
AI-generated classification rationale, not a full analysis. Verify with the original CSSF source before acting. Full disclaimer.
What the CSSF said
CVE-2026-1281 & CVE-2026-1340
Published by CSSF . Read the full notice at the source for the authoritative text.
Context
Commission de Surveillance du Secteur Financier (CSSF) — Luxembourg financial regulator. We track 560 updates from them.
Luxembourg's CSSF regulates the investment fund industry. Browse all Luxembourg updates.
This update is classified under Operational Resilience / Outsourcing, Technology & Cyber, Reporting & Disclosure and Banking & Credit.