Cybersecurity — 2026-04-12
CISA Adds Second Critical Ivanti EPMM Flaw to Exploited Vulnerabilities Catalog, Orders Sunday Patch Deadline
CISA added CVE-2026-1340, a critical code injection vulnerability in Ivanti Endpoint Manager Mobile with a CVSS score of 9.8, to its Known Exploited Vulnerabilities catalog. The flaw enables unauthenticated remote code execution and is the second critical Ivanti EPMM vulnerability added since January. Exploitation began shortly after a proof-of-concept was released. Federal civilian agencies were ordered to patch by April 11. Ivanti released a fix in version 12.8 on March 18, but the addition to KEV indicates active exploitation continues against unpatched systems.
2 sources
- CISA orders feds to patch exploited Ivanti EPMM flaw by Sunday - Bleeping Computer
- CISA adds second critical flaw in Ivanti EPMM to exploited vulnerabilities catalog - Cybersecurity Dive
View in full brief →