logo

CISA Urges Urgent Patching of Critical Ivanti EPMM Vulnerability CVE-2026-1340

ID: 6719e4c3-8306-58ed-8708-d0bce28d0981

STIX ID: report--6719e4c3-8306-58ed-8708-d0bce28d0981

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-09

...
...

CISA has issued an urgent advisory for a critical Ivanti Endpoint Manager Mobile vulnerability (CVE-2026-1340) — an unauthenticated code injection/RCE with a CVSS of 9.8 — confirming active exploitation and adding it to the Known Exploited Vulnerabilities catalog; federal agencies are mandated to patch by April 11, 2026 under BOD 22-01, and roughly 950 exposed Ivanti EPMM endpoints remain reachable online.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.