U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog

2026-04-09T02:51:49Za1ead4cab125be98ad353003085383f279da37b7bd0a4df53e8a1018662f33dc
active-exploitationanthropicapt28cisaclaude-mythoscve-2025-59528cve-2026-1340cve-2026-35616flowisefortinetgpugpubreachhospital-attackiran-linked-actorsivantiknown-exploited-vulnerabilitiesmedusa-ransomwareplcprismexproject-glasswingrockwell-allen-bradleyrowhammersignature-healthcaresteganographystorm-1175

What happened

Feed highlights multiple high-impact incidents and vulnerabilities: CISA added Ivanti EPMM code-injection CVE-2026-1340 (CVSS 9.8) and Fortinet FortiClient EMS CVE-2026-35616 (CVSS 9.1) to its Known Exploited Vulnerabilities catalog; a critical Flowise remote-code-execution flaw CVE-2025-59528 (CVSS 10.0) is being actively exploited; Iran-linked APTs are scanning/exploiting internet-exposed Rockwell/Allen‑Bradley PLCs in critical infrastructure; Russia-linked APT28 (Fancy Bear) is running a spear‑phishing campaign deploying a new PRISMEX malware suite using steganography against Ukraine and盟/​

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
a1ead4cab125be98ad353003085383f279da37b7bd0a4df53e8a1018662f33dc
Enrichment time
2026-04-09T02:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.