Federal cybersecurity authorities have updated the Known Exploited Vulnerabilities catalog to mandate urgent remediation across federal civilian agencies for two critical enterprise perimeter flaws. Unauthenticated threat actors are actively weaponizing both vulnerabilities to execute operating system commands and deploy persistent web backdoors across commercial and government networks.
The catalog additions feature Ivanti Endpoint Manager Mobile EPMM API routing vulnerability CVE-2026-38291 alongside Palo Alto Networks PAN-OS management interface input validation vulnerability CVE-2026-40112. Threat telemetry confirms adversaries transmitting malformed HTTP POST queries to bypass authentication handlers, spawning root shell processes on target firewall management panels and mobile device management appliances. Under Binding Operational Directive 26-04, federal civilian executive branch agencies face a mandatory September 30 compliance deadline to apply official vendor maintenance builds and conduct forensic assessments.
Subverting central firewall management interfaces and mobile device management platforms destroys perimeter access security boundaries. Because these management controllers govern network routing rules, SSL VPN tunnel terminations, and mobile device security profiles, an unauthenticated takeover permits threat actors to disable security inspection rules, extract employee credentials, and pivot into internal subnets.
– Apply official security maintenance updates released by Ivanti across all EPMM server deployments immediately.
– Force immediate installation of PAN-OS maintenance builds across all Palo Alto Networks firewall management panels.
– Restrict public internet visibility of firewall management interfaces and MDM web portals by placing panels on isolated management VLANs.
– Inspect application access logs for malformed HTTP requests targeting internal diagnostic and API routing endpoints.
Perimeter security infrastructure protection demands rapid security patch deployment and strict interface isolation to ensure central management controllers remain protected from unauthenticated remote command execution. #CodeDefence #Ivanti #EPMM #PaloAltoNetworks #PANOS #CISA #KEV #RCE #NetworkSecurity
/
