logo

U.S. Cybersecurity Agency Warns of Actively Exploited Ivanti EPMM Vulnerability

ID: 6c151fd2-a6f9-5476-98dc-64c9076aa18c

STIX ID: report--6c151fd2-a6f9-5476-98dc-64c9076aa18c

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-01-19

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report describes active exploitation of critical Ivanti vulnerabilities (notably CVE-2023-35082 and high‑severity VPN flaws) that allow authentication bypass and remote code execution; attackers have used these to drop web shells and backdoors across many sectors worldwide, with over 2,100 devices observed compromised and a suspected Chinese actor (UTA0178) implicated. Rapid7, Volexity, Assetnote and others documented chaining and evasive modifications, while Ivanti and CISA have issued mitigations and advisories—organizations are urged to apply vendor fixes and rotate secrets after rebuilds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.