惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
罗磊的独立博客
雷峰网
雷峰网
量子位
V
Visual Studio Blog
Vercel News
Vercel News
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The Cloudflare Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
宝玉的分享
宝玉的分享
月光博客
月光博客
Martin Fowler
Martin Fowler
aimingoo的专栏
aimingoo的专栏
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Microsoft Security Blog
Microsoft Security Blog
博客园 - 叶小钗
腾讯CDC
Engineering at Meta
Engineering at Meta
博客园 - Franky
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
Jina AI
Jina AI
A
About on SuperTechFans

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
CISA adds second critical flaw in Ivanti EPMM to exploite...
David Jones · 2026-04-09 · via Cybersecurity Dive - Latest News

An article from site logo

The code injection flaw is similar to a prior vulnerability that was immediately flagged in January.

Published April 9, 2026

A close-up digital illustration portrays cybersecurity with a futuristic theme

Getty Images

The Cybersecurity and Infrastructure Security Agency on Wednesday added a critical flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalog. 

The vulnerability, tracked as CVE-2026-1340, stems from a code injection in Ivanti EPMM that allows an attacker to achieve remote code execution without authentication. 

CISA set a deadline of April 11 for federal civilian executive branch agencies to mitigate their environments.  

Ivanti first disclosed the issue in late January along with CVE-2026-1281, which is a similar code injection vulnerability and was immediately added to the KEV catalog. Both flaws have a severity score of 9.8. The company said it began seeing exploitation shortly after a proof of concept was released. 

Ivanti released a security advisory for the vulnerabilities at the time, and said it was aware of a “very limited number” of customers whose products were impacted. 

“At the time of disclosure, Ivanti provided an RPM package to protect customer environments, which requires no downtime and takes only seconds to apply,” an Ivanti spokesperson told Cybersecurity Dive. 

Ivanti also provided indicators of compromise, technical analysis and a detection script developed alongside the National Cyber Security Centre in the Netherlands. 

The European Commission and Dutch authorities said they were investigating incidents related to the vulnerabilities back in February. 

Ivanti released version 12.8 for EPMM back on March 18, which resolves the vulnerabilities and provides additional security hardening features, according to a spokesperson. The company recommends all users apply the upgrade. 

Multiple security researchers contacted by Cybersecurity Dive said they have not seen any recent change in threat activity that would explain why the vulnerability was finally added to the KEV catalog. 

“It's been repeatedly exploited literally thousands of times since it was disclosed,” Simo Kohonen, founder and CEO at Defused, told Cybersecurity Dive.

CISA did not provide any specifics about the timing behind the change in status, but provided a link to general guidance for why a vulnerability is added to the KEV catalog.