SafeITExperts

SafeITExperts

Your expert guide to cybersecurity and digital privacy. Security hardening for all platforms : Windows, macOS, Linux, and Android. Solutions aligned standards : NIST and ANSSI for comprehensive digital protection.


Cyberattacks Vulnerabilities monthly Panorama

Publié par Marc sur 27 Avril 2026, 15:15pm

Catégories : #cyber-attacks-april-2026, #Patch-Tuesday-april-2026, #data-leaks-France-2026, #Linux-kernel-vulnerabilities

April 2026 cybersecurity panorama: active CERT-FR alerts (F5 BIG-IP, Ivanti EPMM CVE-2026-1281/1340), Microsoft Patch Tuesday, Fortinet, Mozilla, Linux (Ubuntu/SUSE/Red Hat) vulnerabilities, French data breach report, ANSSI 2025 overview. SafeITExperts guide.

April 2026 cybersecurity panorama: active CERT-FR alerts (F5 BIG-IP, Ivanti EPMM CVE-2026-1281/1340), Microsoft Patch Tuesday, Fortinet, Mozilla, Linux (Ubuntu/SUSE/Red Hat) vulnerabilities, French data breach report, ANSSI 2025 overview. SafeITExperts guide.

ALERT: Ivanti EPMM CVE-2026-1281/1340 actively exploited F5 BIG-IP APM CVE-2025-53521 RCE — patch now France data breach: OFII (2.1M) & Cegedim Sante (15M) CERT-FR active alerts: 3 (ALE-001, -003, -004) Linux kernel CVSS 9.8 — Ubuntu, SUSE, Red Hat Microsoft Patch Tuesday April 2026: Azure Linux CVE-2026-34714 (CVSS 9.2) GLPI: three critical CVEs (RCE, SQLi, XSS) with public PoC ANSSI 2025 report: 460 possible leaks, 42% confirmed ALERT: Ivanti EPMM CVE-2026-1281/1340 actively exploited F5 BIG-IP APM CVE-2025-53521 RCE — patch now France data breach: OFII (2.1M) & Cegedim Sante (15M) CERT-FR active alerts: 3 (ALE-001, -003, -004) Linux kernel CVSS 9.8 — Ubuntu, SUSE, Red Hat Microsoft Patch Tuesday April 2026: Azure Linux CVE-2026-34714 (CVSS 9.2) GLPI: three critical CVEs (RCE, SQLi, XSS) with public PoC ANSSI 2025 report: 460 possible leaks, 42% confirmed
Menu

Cyber Attacks & Vulnerabilities
April 2026 Panorama

Active CERT-FR alerts, ongoing exploitation (Ivanti EPMM, F5 BIG-IP), Patch Tuesday, data leaks in France
April 17, 2026 Updated: 04/17/2026 v1 Reading time: ~14 min 1 Panorama
🚨 CERT-FR 🔓 Ivanti EPMM 🌐 F5 BIG-IP 🪟 Patch Tuesday 🐧 Linux Kernel 🇫🇷 FR Leaks
1
Cybersecurity panorama — April 2026

📖 Introduction

Context

April 2026 confirms a strong trend: attackers are actively exploiting critical vulnerabilities within days of their disclosure. Three CERT-FR alerts are currently open, the April Patch Tuesday fixes dozens of Microsoft flaws, and France is experiencing a new wave of massive data leaks (OFII, Cegedim Sante, France Travail). This panorama synthesizes the facts and provides priority actions for IT teams and CISOs.

3D cybersecurity visualization: attacked server, active alerts, digital locks
🔐 Illustration: April 2026 cyber attacks panorama – SafeITExperts
Active CERT-FR alerts
3
Ivanti EPMM, F5 BIG-IP, instant messaging
CERT-FR advisories (week 15)
26
April 6–12, 2026 (AVI-0399 to AVI-0424)
ANSSI 2025 events
4,386+
Based on 2024 — confirmed increase in 2025
CNIL fine — France Travail
€5M
Sanction on January 29, 2026

🚨 Three ongoing CERT-FR alerts

As of April 17, 2026, three CERT-FR alerts remain open. An alert means that active exploitation is observed or an ongoing campaign targets French organizations. This is the strongest signal published by ANSSI: absolute priority in the patching queue.

ReferenceProduct / ContextCVESeverityPublished
CERTFR-2026-ALE-004F5 BIG-IP APMCVE-2025-53521EXPLOITED03/31/2026
CERTFR-2026-ALE-003Targeted instant messaging campaigns (sovereign sectors)CRITICAL03/20/2026
CERTFR-2026-ALE-001Ivanti Endpoint Manager Mobile (EPMM)CVE-2026-1281, CVE-2026-1340EXPLOITED01/30/2026
🔓 Ivanti EPMM – CVE-2026-1281 & CVE-2026-1340

Unauthenticated remote code execution (CVSS 9.8) via Bash expansion. Confirmed exploitation: Dutch Data Protection Authority and Council for the Judiciary compromised. More than 4,400 exposed instances (Palo Alto).

Affected versions: 12.5.0.0 to 12.7.0.0.

CERTFR-2026-ALE-001 · KEV CISA
🌐 F5 BIG-IP APM – CVE-2025-53521

Unauthenticated RCE on the Access Policy Manager module. F5 confirmed active exploitation on March 29, 2026.

Immediate action: apply the patch and launch a compromise assessment using the IoCs provided by F5.

CERTFR-2026-ALE-004
✉️ Targeted instant messaging campaigns

Targeting WhatsApp, Signal, Telegram. Sovereign sectors targeted: political figures, ministerial executives, journalists.

Vectors: social engineering, pairing QR code hijacking, mobile spyware.

CERTFR-2026-ALE-003
SafeITExperts Rule

Never expose an administration interface (BIG-IP, Ivanti, Fortinet) directly to the Internet. Bastion or VPN mandatory.

2
Critical vulnerabilities — Week 15

📊 Summary table — Week 15 (04/06 → 04/12)

The bulletin CERTFR-2026-ACT-017 synthesizes the significant vulnerabilities of the week. Below is the extract of CVEs with critical or high severity (CVSS ≥ 8.6) published or referenced by CERT-FR.

VendorProductCVECVSSTypeExploit.
FortinetFortiClientEMSCVE-2026-356169.8Bypass + RCEExploited
AdobeAcrobat ReaderCVE-2026-346218.6Code executionExploited
MozillaFirefox, Thunderbird (+ ESR)CVE-2026-57319.8Code execution
MozillaFirefox, Thunderbird (+ ESR)CVE-2026-57349.8Code execution
MozillaFirefox, Thunderbird (+ ESR)CVE-2026-57359.8Code execution
GLPIGLPICVE-2026-260269.1RCEPublic PoC
GLPIGLPICVE-2026-262639.8SQL injection
GLPIGLPICVE-2026-260277.5Stored XSSPublic PoC
UbuntuUbuntu Linux KernelCVE-2025-682639.8Not specified
MicrosoftAzure LinuxCVE-2026-347149.2Code execution
JuniperJSI vLWCCVE-2026-337849.3Security bypass
JuniperCTP OSCVE-2026-337719.1Security bypass
ApacheTomcat 9 / 10 / 11CVE-2025-666149.1Security bypass
🪟 Microsoft – Azure Linux CVE-2026-34714

CVSS 9.2 · Scope Changed. Arbitrary code execution on Azure Linux 2.0/3.0.

Four CERT-FR advisories: AVI-0406, AVI-0414, AVI-0420, AVI-0445.

Patch Tuesday April 2026
🛡️ Fortinet FortiClientEMS – CVE-2026-35616

Security bypass + RCE · CVSS 9.8 · Exploited.

Advisory FG-IR-26-099 of April 4, 2026.

CERTFR-2026-AVI-0400
🦊 Mozilla Firefox & Thunderbird

Three CVEs with CVSS 9.8 (CVE-2026-5731, -5734, -5735). Code execution via web page or email.

MFSA 2026-25 to 2026-29.

No public PoC
Reminder

For Mozilla: restart the browser after updating for the patch to take effect.

3
Linux & open source ecosystem

🐧 Linux kernels — Ubuntu, SUSE, Red Hat

DistributionCERT-FR AdvisoryNotable CVECVSSAction
UbuntuAVI-0421CVE-2025-682639.8apt full-upgrade
SUSE / openSUSEAVI-0422zypper patch
Red Hat / CentOSAVI-0423dnf upgrade
Production tip

kpatch (Red Hat) and kgraft (SUSE) allow applying certain kernel patches without reboot.

🖨️ CUPS & Apache Tomcat

CUPS: CVE-2026-34980 (CVSS 6.1) and CVE-2026-34990 (CVSS 5.0) with public PoC. Apache Tomcat: CVE-2025-66614 (CVSS 9.1) fixed in versions 9.0.116, 10.1.53, 11.0.20 (CERTFR-2026-AVI-0418).

🎫 GLPI — Three critical CVEs

RCE (CVE-2026-26026, CVSS 9.1), SQL injection (CVE-2026-26263, CVSS 9.8) and stored XSS (CVE-2026-26027, CVSS 7.5). Public PoCs for the first two. Urgent update required (CERTFR-2026-AVI-0401).

4
France & ANSSI report

💧 Data leaks — Early 2026 in France

DateEntityImpactSource
01/01/2026OFII2.1M foreigner files, dark web saleJedha
01/12/2026Agglomération d'Hénin-CarvinCyber attack, extent ongoingJedha
01/29/2026France Travail (CNIL fine)€5M fine (2024 incident)CNIL
01/30/2026ManoManoLeak via subcontractorJedha
Early 2026Cegedim Sante~15 million French citizens, health data01net
Notable figure

According to 01net, more than 90 million French accounts were affected by data breaches in early 2026 (including duplicates).

📈 ANSSI 2025 Cyber Threat Panorama

Events handled (2024)
4,386
+15% vs 2023 — upward trend
Possible leaks (2025)
460
42% confirmed, 58% bluff
Ransomware victims
37%
SMEs / very small businesses / mid-caps
Mobile phone alert
Active
Spyware confirmed

🤖 Generative AI and cyber threat

📧 Enhanced phishing

Flawless emails, large‑scale personalization, style imitation.

💻 Exploit development

Offensive code generation, partial bypass of guardrails.

🔍 OSINT reconnaissance

Automated information sorting and synthesis, target profiles.

ANSSI key point

No fully autonomous AI-driven attack confirmed to date. AI is a human efficiency multiplier.

5
Actions & resources

✅ Patching checklist — April 2026

  • 🔴 Ivanti EPMM — RPM 12.x + restart + IoC search. EXPLOITED
  • 🔴 F5 BIG-IP APM — CVE-2025-53521 patch + compromise check. EXPLOITED
  • 🔴 Fortinet FortiClientEMS — FG-IR-26-099 patch. EXPLOITED
  • 🟡 Adobe Acrobat Reader — APSB26-43. Exploited
  • 🟡 Microsoft Windows / Azure Linux — April 2026 Patch Tuesday.
  • 🟡 Mozilla Firefox / Thunderbird — MFSA 2026-25 to 2026-29.
  • 🟡 Linux kernel — Ubuntu / SUSE / Red Hat (AVI-0421 to 0423).
  • 🟡 Apache Tomcat — 9.0.116 / 10.1.53 / 11.0.20.
  • 🟡 GLPI — Patches for the three CVEs (public PoC).
  • 🟢 CUPS — CVE-2026-34980 / CVE-2026-34990 (public PoC).

📌 Analytical conclusion — SafeITExperts

🎯 Industrialization

Criminal and state‑sponsored campaigns are professionalizing. CVE exploitation window is shrinking sharply.

📱 Mobile surface

Instant messaging and decision‑maker endpoints are priority targets (ALE-003).

🧠 Cyber‑bluff

58% of claimed leaks are not confirmed. Measured communication is essential.

🤖 AI: multiplier

AI increases efficiency but does not (yet) replace humans. Vigilance on phishing.

🔧 KEV prioritization

The "patch what bleeds" checklist must become a weekly reflex.

🏛️ ANSSI role

CERT-FR remains the reference source. Subscribe to feeds and integrate IoCs.

SafeITExperts message

Cybersecurity in 2026 requires continuous monitoring, extreme patch reactivity, and measured communication. Do not underestimate the mobile attack surface nor the speed of exploitation of critical flaws.

❓ FAQ — Frequently asked questions

1 What are the active CERT-FR alerts in April 2026?
Three alerts are active as of April 17, 2026: CERTFR-2026-ALE-001 (Ivanti EPMM, CVE-2026-1281 and CVE-2026-1340, actively exploited), CERTFR-2026-ALE-003 (campaigns targeting instant messaging accounts of sovereign sectors), and CERTFR-2026-ALE-004 (F5 BIG-IP APM, CVE-2025-53521, active exploitation confirmed on March 29, 2026). All three must be treated as absolute priority.
2 Is my Ivanti EPMM instance vulnerable to CVE-2026-1281 and CVE-2026-1340?
Yes if it runs version 12.5.0.0, 12.5.1.0, 12.6.0.0, 12.6.1.0 or 12.7.0.0 and earlier. Both flaws (CVSS 9.8) allow unauthenticated remote code execution. CISA added CVE-2026-1281 and CVE-2026-1340 to its KEV catalog with a short patch window. Apply the RPM 12.x.0.x or 12.x.1.x immediately according to your version, then restart EPMM to purge any memory-resident implants. If the instance was exposed to the Internet before patching, consider it scanned and launch a compromise assessment.
3 What should an organization exposing an F5 BIG-IP APM interface to the Internet do?
Apply F5's patch for CVE-2025-53521 (unauthenticated RCE on BIG-IP APM) without delay and launch a compromise assessment using the IoCs provided by the vendor. CERT-FR reminds that exposing an admin interface to the Internet goes against best practices: restrict access to a bastion, an internal VPN, or strict IP filtering. An external surface audit (nmap, Shodan/Censys searches) usefully complements technical remediation.
4 Do the April 2026 Linux kernel vulnerabilities affect workstations?
CERT-FR advisories CERTFR-2026-AVI-0421 (Ubuntu), -0422 (SUSE) and -0423 (Red Hat) affect both server and workstation kernels. Typical impacts are privilege escalation, confidentiality breach and denial of service. Apply updates via apt upgrade, zypper patch or dnf upgrade then reboot — or use kpatch/livepatch depending on the distribution for production servers.
5 What is the status of data breaches in France in early 2026?
According to ANSSI (2025 Cyber Threat Panorama published on March 11, 2026), 460 security events were characterized as possible data leaks in 2025, 42% confirmed — the rest being cyber‑criminal "bluff". In January 2026, OFII announced the theft of 2.1 million foreigner files, and the Cegedim Santé leak exposed nearly 15 million French citizens. The CNIL also fined France Travail €5 million on January 29, 2026 for inadequate data security following the 2024 cyber attack.
6 What is the CISA KEV and why is it important?
The Known Exploited Vulnerabilities Catalog maintained by the US CISA lists CVEs with confirmed real-world exploitation. An entry in the KEV imposes a short remediation deadline on US federal agencies (often 21 days, sometimes less for critical cases like Ivanti EPMM). For a French organization, following the KEV remains good practice: it is one of the best free public indicators to prioritize emergency patches. The catalog is available as structured JSON, integrable into a SIEM or an inventory script.
7 How is generative AI changing the cyberattack landscape in 2026?
In its report CERTFR-2026-CTI-001 published on February 4, 2026, ANSSI observes that generative AI is gradually being integrated into attackers' tooling: more credible phishing emails (no spelling mistakes, large‑scale personalization), generation of offensive code drafts, partial automation of OSINT reconnaissance. No fully autonomous AI-driven attack has been confirmed to date. AI acts as an efficiency multiplier rather than a paradigm shift — classic defenses (MFA, filtering, training) remain relevant but must be raised to a higher level.

🔗 Official sources

📖 5 SafeITExperts guides

Pour être informé des derniers articles, inscrivez vous :
Commenter cet article

Archives

Nous sommes sociaux !

Facebook X Bluesky Mastodon GitHub Reddit RSS

Articles récents