logo

U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog

ID: 72b950fc-6d23-5d96-8061-31b345c3ecd1

STIX ID: report--72b950fc-6d23-5d96-8061-31b345c3ecd1

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CISA added CVE-2026-1340—a critical (CVSS 9.8) code-injection vulnerability in Ivanti Endpoint Manager Mobile that allows unauthenticated remote code execution—to its Known Exploited Vulnerabilities catalog; Ivanti reports limited in-the-wild exploitation, the availability of a public PoC, and has released patches plus an RPM detection tool, while CISA mandates federal remediation by April 11, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.