Featured resource
2025 Tech Upskilling Playbook
Tech Upskilling Playbook

Build future-ready tech teams and hit key business milestones with seven proven plays from industry leaders.

Check it out
  • Course

CVE-2026-1281 Critical Code Injection in Ivanti EPMM: What You Should Know

Discover the key information you need to know about CVE-2025-29927, an authentication bypass vulnerability in the middleware layer in Vercel’s Next.js.

Beginner
11m

Created by Matthew Lloyd Davies and Michael Teske

Last Updated Jan 30, 2026

Course Thumbnail
  • Course

CVE-2026-1281 Critical Code Injection in Ivanti EPMM: What You Should Know

Discover the key information you need to know about CVE-2025-29927, an authentication bypass vulnerability in the middleware layer in Vercel’s Next.js.

Beginner
11m

Created by Matthew Lloyd Davies and Michael Teske

Last Updated Jan 30, 2026

Get started today

Access this course and other top-rated tech content with one of our business plans.

Try this course for free

Access this course and other top-rated tech content with one of our individual plans.

This course is included in the libraries shown below:

  • Security
What you'll learn

CVE-2026-1281 is a critical code injection vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM), scoring 9.8 on the CVSS scale. This flaw allows attackers to achieve unauthenticated remote code execution when specific features are enabled - namely in-house application distribution and Android file transfer configuration. The vulnerability has been added to CISA's "Known Exploited Vulnerabilities" catalog, indicating active exploitation in the wild. Organizations running Ivanti EPMM with these features enabled face immediate risk of compromise, as attackers can execute arbitrary code without authentication. This episode covers the technical mechanics of the vulnerability, exposure conditions, detection strategies, and practical response measures for security teams managing mobile device management infrastructure.

CVE-2026-1281 Critical Code Injection in Ivanti EPMM: What You Should Know
Beginner
11m
Table of contents

About the author
Matthew Lloyd Davies - Pluralsight course - CVE-2026-1281 Critical Code Injection in Ivanti EPMM: What You Should Know
Matthew Lloyd Davies
43 courses 4.7 author rating 47 ratings

Matt has a degree in Chemical engineering and a PhD in mathematical chemistry. He is also a GIAC certified incident handler and penetration tester and has regulated cyber security in the UK civil nuclear sector for many years.

About the author
Michael Teske - Pluralsight course - CVE-2026-1281 Critical Code Injection in Ivanti EPMM: What You Should Know
Michael Teske
73 courses 4.5 author rating 888 ratings

Michael Teske is an Author Evangelist with Pluralsight helping people elevate their skills. He has 20+ years of experience in IT Ops, including 17 as an IT instructor at a community college.

2025 Forrester Wave™ names Pluralsight as a Leader among tech skills dev platforms

See how our offering and strategy stack up.

forrester wave report