U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalog
2026-04-09T02:51:49Z•a1ead4cab125be98ad353003085383f279da37b7bd0a4df53e8a1018662f33dc
active-exploitationanthropicapt28cisaclaude-mythoscve-2025-59528cve-2026-1340cve-2026-35616flowisefortinetgpugpubreachhospital-attackiran-linked-actorsivantiknown-exploited-vulnerabilitiesmedusa-ransomwareplcprismexproject-glasswingrockwell-allen-bradleyrowhammersignature-healthcaresteganographystorm-1175
What happened
Feed highlights multiple high-impact incidents and vulnerabilities: CISA added Ivanti EPMM code-injection CVE-2026-1340 (CVSS 9.8) and Fortinet FortiClient EMS CVE-2026-35616 (CVSS 9.1) to its Known Exploited Vulnerabilities catalog; a critical Flowise remote-code-execution flaw CVE-2025-59528 (CVSS 10.0) is being actively exploited; Iran-linked APTs are scanning/exploiting internet-exposed Rockwell/Allen‑Bradley PLCs in critical infrastructure; Russia-linked APT28 (Fancy Bear) is running a spear‑phishing campaign deploying a new PRISMEX malware suite using steganography against Ukraine and盟/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- a1ead4cab125be98ad353003085383f279da37b7bd0a4df53e8a1018662f33dc
- Enrichment time
- 2026-04-09T02:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.