logo

CISA orders feds to patch exploited Ivanti EPMM flaw by Sunday

ID: dd25b0f9-6bb1-585e-959a-d4374435332f

STIX ID: report--dd25b0f9-6bb1-585e-959a-d4374435332f

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-04-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA has ordered U.S. federal agencies to urgently patch a critical, actively exploited code-injection vulnerability in Ivanti Endpoint Manager Mobile (CVE-2026-1340) after vendor fixes released Jan 29; Shadowserver reports roughly 950 exposed EPMM appliances online and Ivanti confirmed limited in-the-wild exploitation, prompting inclusion in CISA's Known Exploited Vulnerabilities catalog and a binding patch deadline for federal systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.