CISA's list that day

29 January 2026

On CISA added 1 vulnerability to its list of exploited vulnerabilities: CVE-2026-1281 in Ivanti Endpoint Manager Mobile (EPMM). US federal agencies must fix it by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2026-1281Code InjectionIvanti Endpoint Manager Mobile (EPMM)Patch this weekMetasploit module; EPSS 0.990.99

Other changes that day

  1. CVE-2024-9680 Mozilla FirefoxRansomware use: Unknown to Known.
  2. CVE-2024-30088 Microsoft WindowsRansomware use: Unknown to Known.
  3. CVE-2024-49039 Microsoft WindowsRansomware use: Unknown to Known.
  4. CVE-2024-51567 CyberPersons CyberPanelRansomware use: Unknown to Known.
  5. CVE-2026-1281 Ivanti Endpoint Manager Mobile (EPMM)Removed from CISA's list.
  6. CVE-2026-1281 Ivanti Endpoint Manager Mobile (EPMM)Restored to CISA's list.