← Back to Feed

CI Fortify – Advice for isolating vital systems

July 28, 2026 · CISA (US-CERT) · Severity: CRITICAL

CISA added CVE-2025-4427 and CVE-2025-4428 affecting Ivanti Endpoint Manager Mobile to the KEV catalog following evidence of active exploitation by state-sponsored threat actors.

Key Takeaways

  • CISA warns of active exploitation of Ivanti Endpoint Manager Mobile via CVE-2025-4427 and CVE-2025-4428
  • Multiple state-sponsored threat actors are involved in the exploitation campaign
  • Federal agencies must apply mitigations by the specified deadline per BOD 22-01
☕ Buy a Coffee