CVE-2023-39337: Ivanti Endpoint Manager Mobile

Critical severity, CVSS 9.1. EPSS: 1.9% chance of exploitation in the next 30 days.

A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability poses a serious security risk, potentially exposing confidential data and system integrity.

Affected products

  • Ivanti Endpoint Manager Mobile: up to and including 11.9.0; from 11.10.0, before 11.10.0.4 (fixed in 11.10.0.4); from 11.11.0, before 11.11.0.2 (fixed in 11.11.0.2)

Published 2023-11-15. Last modified 2026-06-17.