CVE-2023-35078: Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2023-07-25. EPSS: 100% chance of exploitation in the next 30 days.
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
Affected products
- Ivanti Endpoint Manager Mobile: before 11.8.1.1 (fixed in 11.8.1.1); from 11.9.0, before 11.9.1.1 (fixed in 11.9.1.1); from 11.10, before 11.10.0.2 (fixed in 11.10.0.2)
Published 2023-07-25. Last modified 2026-08-05.