CISA: Critical Ivanti auth bypass bug now actively exploited
ID: a088cda6-730e-54db-8304-b3b7d673b221
STIX ID: report--a088cda6-730e-54db-8304-b3b7d673b221
Feed Name: Bleeping Computer
CISA warns that CVE-2023-35082, a critical unauthenticated API/authentication bypass in Ivanti EPMM and MobileIron Core, is being actively exploited; Rapid7 has published IOCs, thousands of EPMM instances are internet-exposed (including government-linked portals), and CISA added the CVE to its Known Exploited Vulnerabilities catalog while requiring federal patching. The report also references additional Ivanti zero-days (CVE-2023-46805, CVE-2024-21887) under mass exploitation and prior incidents where attackers backdoored many VPN/ICS appliances.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
