Ivanti EPMM January 2026 critical — historical precedent cited in 2026-05-09 Ivanti UPDATE
cve · CVE-2026-1281
Coverage timeline
3
first 2026-05-09 → last 2026-05-10
Briefs
3
3 distinct
Sources cited
34
22 hosts
Sections touched
0
—
Co-occurring entities
0
no co-occurrence
Story timeline
- 2026-05-10CTI Daily Brief — 2026-05-10
- 2026-05-09CTI Daily Brief — 2026-05-09
- 2026-W19CTI Weekly Summary — 2026-W19 (May 04 – May 10, 2026)
Source distribution
- cert.ssi.gouv.fr3 (9%)
- helpnetsecurity.com3 (9%)
- bleepingcomputer.com2 (6%)
- ivanti.com2 (6%)
- labs.watchtowr.com2 (6%)
- nvd.nist.gov2 (6%)
- security-hub.ncsc.admin.ch2 (6%)
- securityaffairs.com2 (6%)
- other16 (47%)
External references
All cited sources (34)
- cert.ssi.gouv.frprimaryinlineCERTFR-2026-ACT-021, 2026-05-11https://www.cert.ssi.gouv.fr/actualite/CERTFR-2026-ACT-021/
- cert.ssi.gouv.frprimaryinlineCERT-FR CERTFR-2026-AVI-0552, 2026-05-07https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0552/
- cert.ssi.gouv.frprimaryinlineCERT-FR CERTFR-2026-AVI-0576, 2026-05-13https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0576/
- bleepingcomputer.cominlineBleepingComputerhttps://www.bleepingcomputer.com/news/security/cisa-gives-feds-3-days-to-patch-ivanti-flaw-exploited-in-attacks/
- bleepingcomputer.cominlineBleepingComputer, 2026-05-07https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-epmm-flaw-exploited-in-zero-day-attacks/
- blog.sekoia.ioinlineSekoia TDR, 2026-06-11https://blog.sekoia.io/apt28-an-evolution-of-tradecraft/
- cert.europa.euinlineCERT-EU 2026-008, 2026-06-10https://cert.europa.eu/publications/security-advisories/2026-008/
- cisa.govinlineCISA AA24-060Ahttps://www.cisa.gov/news-events/cybersecurity-advisories/aa24-060a
- cloud.google.cominlineGoogle Cloud / Mandiant M-Trends 2026, 2026-03-23https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026
- computerweekly.cominlineComputer Weeklyhttps://www.computerweekly.com/news/366642525/They-protect-the-law-while-breaking-it-Inside-Europols-shadow-IT-system
- correctiv.orginlineCorrectiv, 2026-05-05https://correctiv.org/en/europe/2026/05/05/they-protect-the-law-while-breaking-it-inside-europols-shadow-it-system/
- enisa.europa.euinlineENISA, 2026-06-11https://www.enisa.europa.eu/news/cyber-europe-2026-all-eyes-on-the-eus-collective-response-and-resilience
- github.cominlinen8n GHSA-q5f4-99jv-pgg5, 2026-05-18https://github.com/n8n-io/n8n/security/advisories/GHSA-q5f4-99jv-pgg5
- helpnetsecurity.cominlineHelp Net Security, 2026-05-04https://www.helpnetsecurity.com/2026/05/04/france-titres-data-breach-teen-suspect/
- helpnetsecurity.cominlineHelp Net Security, 2026-02-09https://www.helpnetsecurity.com/2026/02/09/european-commission-ivanti-epmm-vulnerabilities/
- helpnetsecurity.cominlineHelp Net Security, 2026-05-08https://www.helpnetsecurity.com/2026/05/08/ivanti-epmm-zero-day-cve-2026-6973/
- ivanti.cominlineIvanti PSIRThttps://www.ivanti.com/blog/may-2026-epmm-security-update
- ivanti.cominlineIvanti PSIRT May 2026 advisory batchhttps://www.ivanti.com/blog/may-2026-security-update
- labs.infoguard.chinlineInfoGuard, 2026-06-09https://labs.infoguard.ch/posts/ghost-sender/
- labs.watchtowr.cominlinewatchTowr Labshttps://labs.watchtowr.com/more-evidence-that-words-dont-mean-what-we-thought-they-meant-ivanti-sentry-pre-auth-os-command-injection-cve-2026-10520/
- labs.watchtowr.cominlinewatchTowr Labs, 2026-06-12https://labs.watchtowr.com/why-use-app-level-auth-when-every-database-has-auth-splunk-enterprise-cve-2026-20253-pre-auth-rce/
- ncsc.nlinlineNCSC-NL — Casus kwetsbaarheden Ivanti EPMM-systemenhttps://www.ncsc.nl/alert/casus-kwetsbaarheden-ivanti-epmm-systemen
- nvd.nist.govinlineNVD — CVE-2026-5787https://nvd.nist.gov/vuln/detail/CVE-2026-5787
- nvd.nist.govinlineNVD — CVE-2026-6973https://nvd.nist.gov/vuln/detail/CVE-2026-6973
- security-hub.ncsc.admin.chinlineNCSC.ch post 12548https://security-hub.ncsc.admin.ch/#/posts/12548
- security-hub.ncsc.admin.chinlineNCSC-CH 12548, 2026-05-08https://security-hub.ncsc.admin.ch/api/posts/12548/details
- securityaffairs.cominlineSecurityAffairshttps://securityaffairs.com/193530/hacking/cve-2026-10520-exploited-ivanti-sentry-gateways-compromised-shortly-after-patch-release.html
- securityaffairs.cominlineSecurity Affairshttps://securityaffairs.com/193557/security/u-s-cisa-adds-ivanti-sentry-flaw-to-its-known-exploited-vulnerabilities-catalog-and-urges-patching-by-june-14.html
- securityweek.cominline2026-05-13https://www.securityweek.com/fortinet-ivanti-patch-critical-vulnerabilities/
- securityweek.cominlineSecurityWeek, 2026-05-08https://www.securityweek.com/ivanti-patches-epmm-zero-day-exploited-in-targeted-attacks/
- thehackernews.cominlineThe Hacker News — Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitationhttps://thehackernews.com/2026/05/ivanti-epmm-cve-2026-6973-rce-under.html
- thehackernews.cominlineThe Hacker News, 2026-05-18https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html
- welivesecurity.cominlineESET WeLiveSecurity, 2026-05-28https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2025-q1-2026/
- wpscan.cominlineWPScan, 2026-06-11https://wpscan.com/vulnerability/68addf8c-9ea6-4b62-9f85-e95350b3992e/
Items in briefs about Ivanti EPMM January 2026 critical — historical precedent cited in 2026-05-09 Ivanti UPDATE
No parsed item heading or body matches this entity yet. Items match by exact CVE id (for CVE entities), by lead-segment substring of the title in the item heading or body, or by a distinctive anchor token from the title appearing in the item heading. Coverage that lives inside a broader section (no per-item heading) is captured by the Story timeline above.