logo

CISA: Critical Ivanti auth bypass bug now actively exploited

ID: a088cda6-730e-54db-8304-b3b7d673b221

STIX ID: report--a088cda6-730e-54db-8304-b3b7d673b221

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-01-18

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA warns that CVE-2023-35082, a critical unauthenticated API/authentication bypass in Ivanti EPMM and MobileIron Core, is being actively exploited; Rapid7 has published IOCs, thousands of EPMM instances are internet-exposed (including government-linked portals), and CISA added the CVE to its Known Exploited Vulnerabilities catalog while requiring federal patching. The report also references additional Ivanti zero-days (CVE-2023-46805, CVE-2024-21887) under mass exploitation and prior incidents where attackers backdoored many VPN/ICS appliances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.