Ivanti disclosed CVE-2023-35081, a high-severity remote file write vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that affects supported versions 11.10, 11.9, and 11.8, with older releases also considered at risk. The flaw carries a CVSS score of 7.2 and was patched by Ivanti after coordinated disclosure.
Security reporting said attackers have exploited CVE-2023-35081 together with CVE-2023-35078 to write malicious JSP and Java .class files to vulnerable EPMM servers. Those files were then loaded by Apache Tomcat, allowing remote execution of attacker-supplied Java bytecode. CISA and Norway’s NCSC-NO issued a joint advisory on active exploitation, and CISA added both vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
CISA and Norway’s National Cyber Security Centre issued a joint advisory titled “Threat Actors Exploiting Ivanti EPMM Vulnerabilities” covering active exploitation of CVE-2023-35078 and CVE-2023-35081. The advisory included indicators of compromise and tactics, techniques, and procedures.
Ivanti disclosed CVE-2023-35081, a high-severity remote file write vulnerability in Ivanti Endpoint Manager Mobile, and released a patch in coordination with its disclosure. Ivanti said supported EPMM versions 11.10, 11.9, and 11.8 were affected, with older releases also at risk.
CISA added both CVE-2023-35078 and CVE-2023-35081 to its Known Exploited Vulnerabilities Catalog after exploitation was observed. The references do not provide an explicit date for these catalog additions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.