April 2026 cybersecurity panorama: active CERT-FR alerts (F5 BIG-IP, Ivanti EPMM CVE-2026-1281/1340), Microsoft Patch Tuesday, Fortinet, Mozilla, Linux (Ubuntu/SUSE/Red Hat) vulnerabilities, French data breach report, ANSSI 2025 overview. SafeITExperts guide.
Cyber Attacks & Vulnerabilities
April 2026 Panorama
Table of Contents
📖 Introduction
April 2026 confirms a strong trend: attackers are actively exploiting critical vulnerabilities within days of their disclosure. Three CERT-FR alerts are currently open, the April Patch Tuesday fixes dozens of Microsoft flaws, and France is experiencing a new wave of massive data leaks (OFII, Cegedim Sante, France Travail). This panorama synthesizes the facts and provides priority actions for IT teams and CISOs.
🚨 Three ongoing CERT-FR alerts
As of April 17, 2026, three CERT-FR alerts remain open. An alert means that active exploitation is observed or an ongoing campaign targets French organizations. This is the strongest signal published by ANSSI: absolute priority in the patching queue.
| Reference | Product / Context | CVE | Severity | Published |
|---|---|---|---|---|
| CERTFR-2026-ALE-004 | F5 BIG-IP APM | CVE-2025-53521 | EXPLOITED | 03/31/2026 |
| CERTFR-2026-ALE-003 | Targeted instant messaging campaigns (sovereign sectors) | — | CRITICAL | 03/20/2026 |
| CERTFR-2026-ALE-001 | Ivanti Endpoint Manager Mobile (EPMM) | CVE-2026-1281, CVE-2026-1340 | EXPLOITED | 01/30/2026 |
Unauthenticated remote code execution (CVSS 9.8) via Bash expansion. Confirmed exploitation: Dutch Data Protection Authority and Council for the Judiciary compromised. More than 4,400 exposed instances (Palo Alto).
Affected versions: 12.5.0.0 to 12.7.0.0.
CERTFR-2026-ALE-001 · KEV CISAUnauthenticated RCE on the Access Policy Manager module. F5 confirmed active exploitation on March 29, 2026.
Immediate action: apply the patch and launch a compromise assessment using the IoCs provided by F5.
CERTFR-2026-ALE-004Targeting WhatsApp, Signal, Telegram. Sovereign sectors targeted: political figures, ministerial executives, journalists.
Vectors: social engineering, pairing QR code hijacking, mobile spyware.
CERTFR-2026-ALE-003Never expose an administration interface (BIG-IP, Ivanti, Fortinet) directly to the Internet. Bastion or VPN mandatory.
📊 Summary table — Week 15 (04/06 → 04/12)
The bulletin CERTFR-2026-ACT-017 synthesizes the significant vulnerabilities of the week. Below is the extract of CVEs with critical or high severity (CVSS ≥ 8.6) published or referenced by CERT-FR.
| Vendor | Product | CVE | CVSS | Type | Exploit. |
|---|---|---|---|---|---|
| Fortinet | FortiClientEMS | CVE-2026-35616 | 9.8 | Bypass + RCE | Exploited |
| Adobe | Acrobat Reader | CVE-2026-34621 | 8.6 | Code execution | Exploited |
| Mozilla | Firefox, Thunderbird (+ ESR) | CVE-2026-5731 | 9.8 | Code execution | — |
| Mozilla | Firefox, Thunderbird (+ ESR) | CVE-2026-5734 | 9.8 | Code execution | — |
| Mozilla | Firefox, Thunderbird (+ ESR) | CVE-2026-5735 | 9.8 | Code execution | — |
| GLPI | GLPI | CVE-2026-26026 | 9.1 | RCE | Public PoC |
| GLPI | GLPI | CVE-2026-26263 | 9.8 | SQL injection | — |
| GLPI | GLPI | CVE-2026-26027 | 7.5 | Stored XSS | Public PoC |
| Ubuntu | Ubuntu Linux Kernel | CVE-2025-68263 | 9.8 | Not specified | — |
| Microsoft | Azure Linux | CVE-2026-34714 | 9.2 | Code execution | — |
| Juniper | JSI vLWC | CVE-2026-33784 | 9.3 | Security bypass | — |
| Juniper | CTP OS | CVE-2026-33771 | 9.1 | Security bypass | — |
| Apache | Tomcat 9 / 10 / 11 | CVE-2025-66614 | 9.1 | Security bypass | — |
CVSS 9.2 · Scope Changed. Arbitrary code execution on Azure Linux 2.0/3.0.
Four CERT-FR advisories: AVI-0406, AVI-0414, AVI-0420, AVI-0445.
Patch Tuesday April 2026Security bypass + RCE · CVSS 9.8 · Exploited.
Advisory FG-IR-26-099 of April 4, 2026.
CERTFR-2026-AVI-0400Three CVEs with CVSS 9.8 (CVE-2026-5731, -5734, -5735). Code execution via web page or email.
MFSA 2026-25 to 2026-29.
No public PoCFor Mozilla: restart the browser after updating for the patch to take effect.
🐧 Linux kernels — Ubuntu, SUSE, Red Hat
| Distribution | CERT-FR Advisory | Notable CVE | CVSS | Action |
|---|---|---|---|---|
| Ubuntu | AVI-0421 | CVE-2025-68263 | 9.8 | apt full-upgrade |
| SUSE / openSUSE | AVI-0422 | — | — | zypper patch |
| Red Hat / CentOS | AVI-0423 | — | — | dnf upgrade |
kpatch (Red Hat) and kgraft (SUSE) allow applying certain kernel patches without reboot.
🖨️ CUPS & Apache Tomcat
CUPS: CVE-2026-34980 (CVSS 6.1) and CVE-2026-34990 (CVSS 5.0) with public PoC. Apache Tomcat: CVE-2025-66614 (CVSS 9.1) fixed in versions 9.0.116, 10.1.53, 11.0.20 (CERTFR-2026-AVI-0418).
🎫 GLPI — Three critical CVEs
RCE (CVE-2026-26026, CVSS 9.1), SQL injection (CVE-2026-26263, CVSS 9.8) and stored XSS (CVE-2026-26027, CVSS 7.5). Public PoCs for the first two. Urgent update required (CERTFR-2026-AVI-0401).
💧 Data leaks — Early 2026 in France
| Date | Entity | Impact | Source |
|---|---|---|---|
| 01/01/2026 | OFII | 2.1M foreigner files, dark web sale | Jedha |
| 01/12/2026 | Agglomération d'Hénin-Carvin | Cyber attack, extent ongoing | Jedha |
| 01/29/2026 | France Travail (CNIL fine) | €5M fine (2024 incident) | CNIL |
| 01/30/2026 | ManoMano | Leak via subcontractor | Jedha |
| Early 2026 | Cegedim Sante | ~15 million French citizens, health data | 01net |
According to 01net, more than 90 million French accounts were affected by data breaches in early 2026 (including duplicates).
📈 ANSSI 2025 Cyber Threat Panorama
🤖 Generative AI and cyber threat
Flawless emails, large‑scale personalization, style imitation.
Offensive code generation, partial bypass of guardrails.
Automated information sorting and synthesis, target profiles.
No fully autonomous AI-driven attack confirmed to date. AI is a human efficiency multiplier.
✅ Patching checklist — April 2026
- 🔴 Ivanti EPMM — RPM 12.x + restart + IoC search. EXPLOITED
- 🔴 F5 BIG-IP APM — CVE-2025-53521 patch + compromise check. EXPLOITED
- 🔴 Fortinet FortiClientEMS — FG-IR-26-099 patch. EXPLOITED
- 🟡 Adobe Acrobat Reader — APSB26-43. Exploited
- 🟡 Microsoft Windows / Azure Linux — April 2026 Patch Tuesday.
- 🟡 Mozilla Firefox / Thunderbird — MFSA 2026-25 to 2026-29.
- 🟡 Linux kernel — Ubuntu / SUSE / Red Hat (AVI-0421 to 0423).
- 🟡 Apache Tomcat — 9.0.116 / 10.1.53 / 11.0.20.
- 🟡 GLPI — Patches for the three CVEs (public PoC).
- 🟢 CUPS — CVE-2026-34980 / CVE-2026-34990 (public PoC).
📌 Analytical conclusion — SafeITExperts
Criminal and state‑sponsored campaigns are professionalizing. CVE exploitation window is shrinking sharply.
Instant messaging and decision‑maker endpoints are priority targets (ALE-003).
58% of claimed leaks are not confirmed. Measured communication is essential.
AI increases efficiency but does not (yet) replace humans. Vigilance on phishing.
The "patch what bleeds" checklist must become a weekly reflex.
CERT-FR remains the reference source. Subscribe to feeds and integrate IoCs.
Cybersecurity in 2026 requires continuous monitoring, extreme patch reactivity, and measured communication. Do not underestimate the mobile attack surface nor the speed of exploitation of critical flaws.
/image%2F7127247%2F20260427%2Fob_018c0c_cybersecurity.png)