Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, was found to contain multiple serious vulnerabilities that enabled unauthorized access, data exposure, and server compromise. The most prominent flaws, CVE-2023-35078 and CVE-2023-35081, were patched by Ivanti in July 2023 after disclosure that attackers had exploited them against Norwegian organizations and a government agency. CVE-2023-35078 is a critical authentication bypass affecting internet-facing API paths, while CVE-2023-35081 is a directory traversal issue that can let an authenticated administrator write arbitrary files, including webshells; CISA added both to its Known Exploited Vulnerabilities catalog and urged immediate patching and compromise assessment.
Subsequent reporting and vendor disclosures showed the exposure was broader than initially understood. Rapid7 highlighted CVE-2023-35078 as a critical API access flaw, while Ivanti later disclosed CVE-2023-35082, saying additional exploitation paths meant all supported EPMM 11.10, 11.9, and 11.8 versions, along with older MobileIron Core releases, were affected depending on configuration. A joint CISA and NCSC-NO advisory said APT actors used the bugs from at least April through July 2023, leveraging compromised SOHO routers as proxies, deleting Apache logs with a malicious mi.war Tomcat application, conducting LDAP reconnaissance, and likely pivoting through Ivanti Sentry toward internal Exchange systems. More recent dCERT advisories indicate Ivanti EPMM continues to face multiple vulnerabilities, including issues that may allow code execution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
dCERT published advisory 2026-1395 on multiple vulnerabilities affecting Ivanti Endpoint Manager Mobile. This appears to be a later follow-up advisory continuing coverage of the product's vulnerability set.
dCERT issued advisory 2026-0252 covering multiple Ivanti Endpoint Manager Mobile vulnerabilities that could allow code execution. The advisory indicates continued downstream tracking and notification of the Ivanti EPMM flaws.
Ivanti published a blog post explaining that additional exploitation paths depended on EPMM appliance configuration and could allow remote internet-facing attackers to access PII and make limited server changes. The company said its investigation was ongoing and credited Rapid7's Stephen Fewer for coordinated disclosure assistance.
Public reporting highlighted that all supported Ivanti EPMM versions were affected by the vulnerability tied to attacks on Norwegian government entities. The coverage reflected the broadened scope of impacted versions following Ivanti's updated disclosure.
Ivanti disclosed CVE-2023-35082 on August 2, 2023, saying its understanding had expanded beyond MobileIron Core 11.2 and earlier. The company said the issue affects all EPMM 11.10, 11.9, and 11.8 versions as well as MobileIron Core 11.7 and below, and released an RPM mitigation script.
CISA and NCSC-NO issued a joint advisory describing active exploitation of CVE-2023-35078 and CVE-2023-35081 against Norwegian organizations. The advisory included technical indicators, tradecraft details, and incident response guidance, including evidence of proxying through compromised SOHO routers and likely Exchange webshell activity.
In late July 2023, CISA added both Ivanti EPMM vulnerabilities to its Known Exploited Vulnerabilities Catalog. This reflected confirmed active exploitation and increased urgency for federal and private-sector defenders to patch.
CISA published an alert highlighting Ivanti security updates for CVE-2023-35081 in EPMM. The vulnerability was described as a directory traversal issue that could let an authenticated administrator write arbitrary files, including webshells.
Rapid7 publicly detailed CVE-2023-35078 as a critical API access vulnerability in Ivanti Endpoint Manager Mobile. The publication helped document the flaw's severity and exploitation risk.
Ivanti released security updates for Ivanti Endpoint Manager Mobile to address CVE-2023-35078, a critical authentication bypass vulnerability. The flaw allowed unauthenticated access to sensitive API paths and exposure of user and device-management data.
According to the joint CISA and NCSC-NO advisory, threat actors exploited Ivanti EPMM vulnerability CVE-2023-35078 from at least April 2023. The activity targeted several Norwegian organizations and ultimately contributed to the compromise of a Norwegian government agency.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
dcert.de
Open sourcedcert.de
Open sourceivanti.com
Open sourcetherecord.media
Open sourcecisa.gov
Open sourcerapid7.com
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.