Ivanti disclosed CVE-2023-35078, a critical authentication bypass in Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, that affects supported 11.10, 11.9, 11.8, and 11.4 release lines, with older versions also at risk. The flaw allows an unauthenticated internet-facing attacker to reach API v2 endpoints, exposing users’ personally identifiable information and enabling limited server changes. Norway’s National Security Authority warned of the zero-day, and Ivanti released patches for supported versions along with an RPM-based mitigation for older deployments.
CISA later warned that threat actors were actively exploiting Ivanti EPMM vulnerabilities, while mnemonic reported that CVE-2023-35078 was used in the compromise of Norway’s Government Security and Service Organisation, affecting 12 ministries. Mnemonic also identified a second zero-day, CVE-2023-35081, a remote file write vulnerability, and said it was exploited in tandem with the authentication bypass. CISA and Norway’s NCSC-NO issued joint guidance, and both flaws were added to CISA’s Known Exploited Vulnerabilities catalog as defenders were urged to patch exposed systems and review logs for suspicious API path manipulation.

See which actors are running it and whether you're in range.
6 events from the most recent confirmed update back to the earliest known activity.
Mnemonic reported discovering a second zero-day in Ivanti EPMM, CVE-2023-35081, and observed it being actively exploited together with CVE-2023-35078. The flaw is a remote file write vulnerability.
CISA and Norway’s National Cyber Security Centre released a joint advisory titled "Threat Actors Exploiting Ivanti EPMM Vulnerabilities" covering active exploitation of CVE-2023-35078 and CVE-2023-35081. The advisory included indicators of compromise and TTPs.
Ivanti publicly disclosed a second Ivanti EPMM zero-day vulnerability, CVE-2023-35081, a remote file write flaw. A patch was made available for the issue.
Ivanti disclosed the Ivanti EPMM vulnerability CVE-2023-35078, saying it affects supported 11.10, 11.9, 11.8, and 11.4 release lines as well as older versions. The company released patches for supported versions and an RPM remediation script for earlier versions, and said exploitation could expose users’ personally identifiable information and allow limited server changes.
The Norwegian Government Security and Service Organisation (DSS) and the Norwegian National Security Authority (NSM) publicly disclosed that a zero-day vulnerability had been exploited in an attack on DSS. The attack affected 12 Norwegian ministries.
The Dutch National Cyber Security Centre warned that CVE-2023-35078 in Ivanti Endpoint Manager Mobile was being exploited on a limited scale and urged organizations to install Ivanti's security updates. It reported roughly 2,900 internet-exposed EPMM instances, including an estimated 80 in the Netherlands, and noted exploitation could expose sensitive data or lead to full system compromise.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 198 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
mnemonic.io
Open sourcensm.no
Open sourcecisa.gov
Open sourcencsc.nl
Open sourcensm.no
Open sourceivanti.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.