U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog
ID: 72b950fc-6d23-5d96-8061-31b345c3ecd1
STIX ID: report--72b950fc-6d23-5d96-8061-31b345c3ecd1
Feed Name: Security Affairs
Threat Score
CISA added CVE-2026-1340—a critical (CVSS 9.8) code-injection vulnerability in Ivanti Endpoint Manager Mobile that allows unauthenticated remote code execution—to its Known Exploited Vulnerabilities catalog; Ivanti reports limited in-the-wild exploitation, the availability of a public PoC, and has released patches plus an RPM detection tool, while CISA mandates federal remediation by April 11, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
