Correction: Report previously published at this URL did not meet our verification standards
What was published
A report previously at this URL described "CVE-2026-28401" as an Ivanti Connect Secure supply-chain remote code execution vulnerability with a CVSS score of 10.0, exploitation by multiple nation-state actors, and an associated CISA emergency directive.
What verification found
- The official NVD record for CVE-2026-28401 describes a stored XSS vulnerability in NocoDB — not an Ivanti product.
- CVE-2026-28401 does not appear in the CISA Known Exploited Vulnerabilities catalog.
- No CISA emergency directive corresponding to the described event could be verified.
The report's central claims could not be sourced to any primary authority and have been retracted in full.
Verified Ivanti threat intelligence
For confirmed, KEV-listed Ivanti vulnerabilities under active exploitation, see the primary records:
- CVE-2026-10520 — Ivanti Sentry OS command injection (CISA KEV, added 2026-06-11)
- CVE-2026-6973 — Ivanti EPMM improper input validation (CISA KEV, added 2026-05-07)
- CVE-2026-1340 — Ivanti EPMM code injection (CISA KEV, added 2026-04-08)
Our sourcing standard
Every CYBERDUDEBIVASH SENTINEL APEX vulnerability report is expected to trace its claims to primary sources: the NVD record, the CISA KEV catalog, and the vendor's own advisory. This report failed that standard. We identified it in an internal editorial-integrity audit, retracted it, and removed it from all platform surfaces. Corrections are published openly because verifiable accuracy — not volume — is the product.