Threat actors exploited two zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), tracked as CVE-2026-1281 and CVE-2026-1340. The incidents add to recurring exploitation of Ivanti EPMM and Connect Secure appliances, which remain attractive entry points for both state-sponsored and financially motivated operators.
A joint Tenable and SentinelOne analysis found that disparate actor groups converge on the same edge and remote-access vendors even when they use different vulnerabilities: its dataset covered 82 CVEs and 93 actor-attribution pairs, with only 21% CVE overlap but 79% vendor overlap. Organizations should prioritize patching internet-facing Ivanti and other edge devices, reduce exposed attack surface, enforce edge-specific remediation SLAs, and use endpoint controls to limit post-compromise lateral movement.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
The 2026 Verizon Data Breach Investigations Report found that median patch time increased year over year from 32 to 43 days, while exploitation surpassed credential theft as the leading initial-access vector.
The 2025 Verizon Data Breach Investigations Report found that only 54% of edge-device Known Exploited Vulnerabilities had been fully remediated.
A China-nexus actor chained CVE-2024-8963 and CVE-2024-8190 against an Ivanti Cloud Services Appliance and collected SSH keys and other stored credentials.
CVE-2026-15409 in SonicWall SMA1000 was attributed to both UTA0533 and INC Ransomware.
In three SentinelOne DFIR engagements, attackers accessed FortiGate management planes and created rogue administrator accounts. In two cases they exported device configurations and extracted credentials; one intrusion involved LDAP bind credentials later used in the environment and the addition of two suspicious Active Directory computers.
A joint Tenable and SentinelOne analysis identified 82 distinct CVEs and 93 CVE-actor attribution pairs involving about 39 named threat actors. It found 12 CVEs exploited by actors from multiple state-sponsored or criminal nexus categories, highlighting recurrent exploitation across edge and remote-access products.
Fortinet later disclosed CVE-2026-24858, which could permit cross-customer device logins under specified FortiCloud SSO conditions.
CVE-2026-1281 and CVE-2026-1340, zero-day vulnerabilities affecting Ivanti Endpoint Manager Mobile, were reported as exploited.
Fortinet disclosed CVE-2025-59718, an authentication bypass in FortiCloud SSO integration affecting FortiOS and other products.
During a FortiManager DFIR engagement, CVE-2024-47575 allowed an unauthorized device to register with the appliance. The attacker subsequently staged an archive of managed-device configurations.
PurpleHaze, assessed as China-linked, and Fox Kitten, assessed as Iran-linked, independently exploited CVE-2024-24919 in Check Point Quantum products.
UTA0218, assessed as China-linked, and INC Ransomware independently exploited CVE-2024-3400 in PAN-OS GlobalProtect.
In a separate case, an actor chained CVE-2023-34133, CVE-2023-34132, and CVE-2023-34124 against an internet-facing SonicWall GMS console. The actor created administrative accounts and used shared managed-service-provider access to reach multiple customer environments.
APT29, assessed as Russia-linked, and Lazarus, assessed as DPRK-linked, independently exploited CVE-2023-42793 in JetBrains TeamCity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
sentinelone.com
Open sourcetenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.