← Back to list

Threat and Vulnerabilities Report - April 2026

Summary

Loginsoft · 2026-05-06 12:59 · 0 claps · 2.7 min read
#cybersecurity #lovi #cisakev #april-2026 #threatintel
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity 🥊 · Combat Sports

Threat and Vulnerabilities Report - April 2026

Summary

April 2026 highlighted a threat landscape where recency no longer defines risk, as both newly disclosed and long-standing vulnerabilities were actively leveraged across diverse environments. The Cybersecurity and Infrastructure Security Agency added 31 vulnerabilities to its KEV catalog, spanning major vendors such as Microsoft, Cisco, Fortinet, Adobe, Google, and others, including flaws dating back to 2012 and 2009. This mix of legacy and current vulnerabilities underscores persistent exposure in unpatched systems and the continued effectiveness of older exploits. In parallel, active exploitation was observed across a wide range of platforms, including widely used web applications, open-source tools, AI frameworks, and network devices such as Ninja Forms, Qinglong, Oracle products, Weaver, MajorDoMo, Nginx-ui, LMDeploy, LiteLLM, ShowDoc, Flowise AI, TP-Link, TBK, and Huawei systems. The breadth of affected technologies reflects a rapidly expanding attack surface, where attackers are simultaneously exploiting enterprise software, developer tools, and IoT infrastructure. Ransomware activity remained consistently high throughout the month, with Qilin ransomware leading with 98 affected organizations, followed by Thegentlemen ransomware (75), DragonForce ransomware (63), and Akira ransomware (47). Additional activity from groups such as LockBit5, IncRansom, and NightSpire ransomware further contributed to the overall threat volume, underscoring sustained pressure across multiple sectors. The distribution of incidents highlights continued operational momentum among both established and emerging ransomware groups, reinforcing the persistence of financially motivated attacks.

Vulnerabilities added to the CISA KEV catalog in April 2026

April 2026 recorded 31 new additions to the Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities (KEV) catalog, reflecting sustained and widespread exploitation activity across the threat landscape. The newly listed vulnerabilities impacted major vendors including Microsoft, Cisco, Fortinet, Adobe, and Google, alongside platforms such as SimpleHelp, ConnectWise, Samsung, D-Link, WebPros, Marimo, TrueConf, Apache, JetBrains, Quest, Kentico, PaperCut, and Synacor. Notably, the catalog included both recently disclosed 2026 vulnerabilities and legacy flaws dating back to 2012 and 2009, underscoring the continued exploitation of unpatched systems. The steady volume of KEV additions, combined with active exploitation across enterprise software, open-source tools, and network infrastructure, highlights persistent adversary focus on high-impact and widely deployed technologies.

Actively Exploited Vulnerabilities in April 2026

April 2026 witnessed sustained real-world exploitation across a broad range of enterprise, application-layer, and IoT technologies, reflecting continued attacker focus on diverse and widely exposed environments. Active abuse was observed in platforms such as Ninja Forms, Qinglong, Oracle products, Weaver, MajorDoMo, Nginx-ui, LMDeploy, LiteLLM, ShowDoc, Flowise AI, as well as network devices from TP-Link, TBK, and Huawei. This activity highlights a convergence of attacks targeting enterprise applications, open-source ecosystems, AI infrastructure, and legacy IoT devices. Exploitation patterns demonstrate rapid weaponization of newly disclosed vulnerabilities alongside continued abuse of older flaws, enabling attackers to achieve initial access, lateral movement, and persistence. These trends reinforce the ongoing reliance on both emerging and legacy vulnerabilities to maximize operational impact across interconnected environments.

Ransomware Insights for April 2026

April 2026 saw sustained ransomware momentum, with Qilin ransomware emerging as the most active group, followed by Thegentlemen ransomware, DragonForce ransomware, and Akira ransomware, reflecting continued competition among both established and emerging extortion operations. Additional activity from groups such as LockBit5, IncRansom, and NightSpire ransomware highlighted a crowded and evolving threat landscape. Activity levels indicated a structured targeting approach across sectors including enterprise services, manufacturing, and critical infrastructure. Threat actors continued to combine vulnerability exploitation, credential abuse, and data exfiltration to reinforce double-extortion strategies and maximize operational impact.

Conclusion

April 2026 reinforced a critical shift in the threat landscape exploitation is no longer bound by vulnerability age, but by opportunity. The month demonstrated how adversaries actively leveraged both newly disclosed flaws and years-old weaknesses across enterprise platforms, developer tools, and IoT ecosystems. The expansion of the Cybersecurity and Infrastructure Security Agency KEV catalog alongside real-world exploitation in platforms such as Qinglong and LiteLLM highlighted a dual trend of rapid weaponization and persistent legacy risk. These developments emphasize that no environment, whether modern AI infrastructure or aging network devices is beyond adversarial reach. Leveraging platforms like Loginsoft Vulnerability Intelligence (LOVI) enables organizations to track active threats, prioritize remediation, and respond with precision to an increasingly dynamic and converged threat landscape.

For more details, check out the full report.


메타데이터
post_id
2b67dc102c6c
slug
threat-and-vulnerabilities-report-april-2026-2b67dc102c6c
url
https://medium.com/@Loginsoft/threat-and-vulnerabilities-report-april-2026-2b67dc102c6c
canonical_url
https://medium.com/@Loginsoft/threat-and-vulnerabilities-report-april-2026-2b67dc102c6c
author_url
https://medium.com/@Loginsoft
status
ok
fetched_at
2026-06-09 15:37:30