← Back to Feed
CI Fortify – Advice for isolating vital systems
July 28, 2026 · CISA (US-CERT) · Severity: CRITICAL
CISA added CVE-2025-4427 and CVE-2025-4428 affecting Ivanti Endpoint Manager Mobile to the KEV catalog following evidence of active exploitation by state-sponsored threat actors.
Key Takeaways
- CISA warns of active exploitation of Ivanti Endpoint Manager Mobile via CVE-2025-4427 and CVE-2025-4428
- Multiple state-sponsored threat actors are involved in the exploitation campaign
- Federal agencies must apply mitigations by the specified deadline per BOD 22-01