---
title: "Cyberattacks Exploit Ivanti Vulnerabilities Affecting EU and Dutch Authorities"
url: https://daily.dev/posts/cyberattacks-exploit-ivanti-vulnerabilities-affecting-eu-and-dutch-authorities-kmbota0n2
source_url: https://daily.dev/posts/cyberattacks-exploit-ivanti-vulnerabilities-affecting-eu-and-dutch-authorities-kmbota0n2
type: collection
source: "Collections"
published: 2026-02-10T14:02:44.848Z
updated: 2026-02-23T22:52:57.701Z
tags: ["cyber", "vulnerability"]
reading_time: 2
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Cyberattacks Exploit Ivanti Vulnerabilities Affecting EU and Dutch Authorities

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

Critical zero-day vulnerabilities CVE-2026-1281 and CVE-2026-1340 in Ivanti EPMM (CVSS 9.8) are being actively exploited, enabling unauthenticated remote code execution on MDM servers. Over 4,400 publicly exposed instances have been targeted across government, healthcare, and manufacturing sectors, with notable breaches at the EU Commission and Dutch government agencies. Ivanti released emergency RPM patches for EPMM 12.x, but patches don't survive version upgrades and connected Sentry systems remain at risk. Security experts recommend reducing public exposure, enforcing strong authentication, restoring from clean backups if compromised, and adopting defense-in-depth and zero-trust strategies.

## Content

Recent cyberattacks exploiting critical zero-day vulnerabilities, CVE-2026-1281 and CVE-2026-1340, in Ivanti Endpoint Manager Mobile (EPMM) have led to significant breaches across governments, healthcare, manufacturing, and other sectors worldwide. These vulnerabilities, both carrying a CVSS score of 9.8, allow attackers to achieve unauthenticated remote code execution on exposed Mobile Device Management (MDM) servers. Over 4,400 instances are publicly accessible, making them prime targets for threat actors deploying web shells, cryptominers, and persistent backdoors that can survive patching cycles.

Ivanti has responded with emergency RPM patches for EPMM version 12.x; however, the patches do not persist through version upgrades, and connected Sentry systems may also be at risk. Organizations are advised to restore systems from clean backups and initiate incident response processes if a compromise is suspected, as patching alone may not suffice.

The EU Commission's MDM system, targeted in late January, was contained within nine hours with minimal data exposure. Similar breaches affected Dutch government agencies, with personal data, including staff names and business contact information, being accessed. Germany and the US see the highest number of compromised instances.

Security experts emphasize robust security measures such as reducing public interface exposure, enforcing strong authentication, and treating perimeter systems as Tier-0 critical infrastructure. As organizations continue to grapple with Ivanti’s repeated vulnerability history, the necessity of a strong defense-in-depth strategy becomes apparent, accompanied by a shift towards continuous monitoring and zero-trust architectures.

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#vulnerability](https://daily.dev/tags/vulnerability)

[View this post on daily.dev](https://daily.dev/posts/cyberattacks-exploit-ivanti-vulnerabilities-affecting-eu-and-dutch-authorities-kmbota0n2)
