logo

How to Respond to Ivanti EPMM/MobileIron Vulnerabilities (CVE-2023-35078) | UpGuard

ID: fea0df47-fc2f-55f7-a5e8-e0a0f29182e2

STIX ID: report--fea0df47-fc2f-55f7-a5e8-e0a0f29182e2

Feed Name: UpGuard Blog

Threat Score
90/100

Date Published: 2024-01-25

Date Updated: 2026-05-01

...
...

This advisory describes critical, actively exploited authentication-bypass and path-traversal vulnerabilities in Ivanti Endpoint Manager Mobile / MobileIron Core (CVE-2023-35078, CVE-2023-35081, CVE-2023-35082) and an Ivanti Sentry bypass (CVE-2023-38035). Affected versions include EPMM 11.8–11.10 and MobileIron Core ≤11.7; attackers can chain flaws to escalate privileges, deploy webshells, create admin accounts, and exfiltrate data. The report documents observed attacks (CISA/KEV listing and NCSC-NO findings), provides mitigation steps (apply Ivanti RPM scripts and upgrade to patched releases), and lists detection checks and IOCs to identify compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.