A critical code-injection vulnerability, CVE-2026-1281, affects Ivanti Endpoint Manager Mobile (EPMM) (formerly MobileIron). According to public advisories and the U.S. CISA Known Exploited Vulnerabilities catalog, the flaw allows an unauthenticated attacker to inject code that can lead to remote code execution on vulnerable EPMM deployments. Ivanti has published security updates and RPM fixes to address the issue; CISA has added the CVE to its KEV catalog, indicating active exploitation risk and elevated urgency for remediation.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

