Third Ivanti Vulnerability Exploited in the Wild, CISA Reports
ID: 0de7e5e2-1aec-5f5c-b4b3-033809906711
STIX ID: report--0de7e5e2-1aec-5f5c-b4b3-033809906711
Feed Name: Dark Reading
Threat Score
Date Published: 2024-01-19
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
...
...
A critical authentication-bypass vulnerability (CVE-2023-35082, CVSS 9.8) affecting Ivanti Endpoint Manager Mobile has been added to CISA's Known Exploited Vulnerabilities catalog; it can act as a patch bypass for CVE-2023-35078 and may be chained with other Ivanti flaws to write malicious web shells, affecting multiple Ivanti EPM versions and prompting urgent patching guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
