CISA Urges Urgent Patching of Critical Ivanti EPMM Vulnerability CVE-2026-1340
ID: 6719e4c3-8306-58ed-8708-d0bce28d0981
STIX ID: report--6719e4c3-8306-58ed-8708-d0bce28d0981
Feed Name: ThreatCluster
Threat Score
CISA has issued an urgent advisory for a critical Ivanti Endpoint Manager Mobile vulnerability (CVE-2026-1340) — an unauthenticated code injection/RCE with a CVSS of 9.8 — confirming active exploitation and adding it to the Known Exploited Vulnerabilities catalog; federal agencies are mandated to patch by April 11, 2026 under BOD 22-01, and roughly 950 exposed Ivanti EPMM endpoints remain reachable online.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
