CVE-2023-35078PoC(ivanti / endpoint_manager_mobile)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (6 mentions)

Immediate actions

  • Patch ivanti endpoint_manager_mobile systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2023-08-15. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-287

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager_mobile

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 3 observed days

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 6 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked at 6 mentions on most recent observed day (2026-07-28)
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
endpoint_manager_mobile

Deep dive

Activity timeline8 mentions / 3d
02356Mentions · 2026-03-08: 1Mentions · 2026-05-03: 1Mentions · 2026-07-28: 6PoC Mentioned / Linked · 2026-03-08: 1PoC Mentioned / Linked · 2026-07-28: 5Exploit Tool / Code · 2026-03-08: 1Exploit Tool / Code · 2026-07-28: 5Active Exploitation · 2026-03-08: 1Active Exploitation · 2026-05-03: 1Patch / Workaround · 2026-03-08: 1Technical Details · 2026-03-08: 1Technical Details · 2026-05-03: 103-0805-0307-28
Signal classification4 categories
PoC
337.5%
Active Exploitation
225.0%
Exploit
225.0%
General
112.5%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-081
Active Exploitation1
2026-05-031
Active Exploitation1
2026-07-286
Exploit2General1PoC3
Full discourse8 posts
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: EGE-GH-I1ejAdv ( CVE-2023-35078 ) EGE-GH-Gcr6LBU ( CVE-2023-35078 ) EGE-GH-9NCRL2F ( CVE-2023-35078 ) EGE-GH-9NSEpRF ( CVE-2023-35078 ) EGE-GH-EoqRtFh ( CVE-2023-35078 ) ..🧵👇

    Post summary

    The daily digest simply lists exploit identifiers linked to CVE-2023-35078 without providing any technical details, PoC references, exploitation evidence, or remediation guidance.

    1102031
    28 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-EoqRtFh [CRITICAL/PoC] Linked: CVE-2023-35078 CVE-2023-35078 🔗 https://exploitgrid.net/exploits/8370c0c5-0edb-45dd-bbee-f3ddb7547890

    Post summary

    The note announces a PoC for CVE-2023-35078, linking to an ExploitGrid entry that likely contains exploitation code, but offers no details on patches, active use, or technical specifics.

    1000037
    28 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-9NSEpRF [CRITICAL/PoC] Linked: CVE-2023-35078 nmap-CVE-2023-35078-Exploit 🔗 https://exploitgrid.net/exploits/7b912728-2896-48d0-b464-e66a87dfbe46

    Post summary

    The post announces a critical PoC and shares a link to an exploit for CVE-2023-35078, indicating ready-to-use attack code, with no evidence of live attacks or patch details.

    1000032
    28 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-9NCRL2F [CRITICAL/PoC] Linked: CVE-2023-35078 CVE-2023-35078 🔗 https://exploitgrid.net/exploits/0772524a-ecd4-40f5-aeda-149e38f49374

    Post summary

    A proof of concept and exploit code for CVE‑2023‑35078 is shared via Exploit‑Grid, but there is no evidence of active exploitation or patch information.

    1000027
    28 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-Gcr6LBU [CRITICAL/PoC] Linked: CVE-2023-35078 CVE-2023-35078 🔗 https://exploitgrid.net/exploits/3989d99c-3c98-4eba-805d-403dbe5d2a76

    Post summary

    A PoC for CVE‑2023‑35078 is shared with a link to an exploit grid resource, but no active exploitation, patch info, or detailed technical data is provided.

    1000028
    28 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-I1ejAdv [CRITICAL/PoC] Linked: CVE-2023-35078 CVE-2023-35078-Exploit-POC 🔗 https://exploitgrid.net/exploits/609bcdc5-6b1a-4f59-950d-3472fafecb88

    Post summary

    A Proof of Concept for CVE-2023-35078 has been shared, with a direct link to exploitgrid.net offering the PoC code.

    1000027
    28 followersView on X
  • Mr.M@MrM_Root
    Active Exploitation

    ⚠️ CVE-2023-35078 en Ivanti Endpoint Manager (MobileIron Core) fue explotado como 0day contra autoridades noruegas, según fuentes no oficiales. La falla permitiría acceso no autenticado a datos corporativos. Entornos con MDM Ivanti: verificar parches de in https://www.bleepingcomputer.com/news/security/norway-says-ivanti-zero-day-was-used-to-hack-govt-it-systems/

    Post summary

    The post alleges CVE‑2023‑35078 was used as a zero‑day to compromise Norwegian government systems for unauthenticated corporate data, but offers no proof of the exploit, specific patches, or PoC details.

    0000080
    5 followersView on X
  • RST Cloud@rst_cloud
    Active Exploitation

    #threatreport #HighCompleteness Mass exploitation of CVE-2026-1281 and CVE-2026-1340 in Ivanti EPMM | 03-03-2026 Source: https://github.security.telekom.com/2026/03/ivanti-CVE-2026-1281-exploitation.html Key details below ↓ 💀Threats: Ncat_tool, Credential_harvesting_technique, Nezha_tool, 🎯Victims: State and local government, Healthcare, Manufacturing, Professional services, Legal services, High technology 🏭Industry: Healthcare, Government 🌐Geo: China, Germany, Australia, German, Canada 🔓CVEs: CVE-2026-1281 \[[Vulners](https://vulners.com/cve/CVE-2026-1281)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.5.0.0, 12.5.1.0, 12.6.0.0, 12.6.1.0, 12.7.0.0) CVE-2023-35078 \[[Vulners](https://vulners.com/cve/CVE-2023-35078)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (<11.8.1.1, <11.9.1.1, <11.10.0.2) CVE-2026-1340 \[[Vulners](https://vulners.com/cve/CVE-2026-1340)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - ivanti endpoint_manager_mobile (le12.7.0.0) 📚TTPs: ⚔️Tactics: 2 🛠️Technics: 0 🤖LLM extracted TTPs:` T1027, T1036, T1046, T1059.004, T1059.009, T1070.004, T1105, T1140, T1190, T1552, ... 🧨IOCs: - File: 7 - IP: 211 - Url: 31 - Hash: 1 - Domain: 3 💽Software: Ivanti EPMM, Ivanti, RPORT, curl, mysql 🔢Algorithms: lzma, base64, sha256 🔠Functions: getMethod, getClass, getParameter, getClassLoader 📜Programming Languages: python, java #threatreport: In early 2026, significant threat activity was reported concerning two recently disclosed critical zero-day vulnerabilities in Ivanti's mobile device management platform, identified as CVE-2026-1281 and CVE-2026-1340. Both vulnerabilities, which receive a CVSS rating of 9.8, allow unauthenticated remote code execution (RCE), making Ivanti Endpoint Manager Mobile (EPMM) appliances prime targets for cyber exploitation. The exploit’s mechanism involves the unsafe handling of attacker-controlled input through a server-side Bash script in an internet-exposed EPMM web endpoint, enabling attackers to execute arbitrary commands without requiring authentication. Following the disclosure by Ivanti on January 29, 2026, the German Federal Office for Information Security (BSI) highlighted ongoing exploitation attempts and advised organizations to adopt enhanced detection measures. The analysis revealed a variety of exploitation patterns, including initial exploitation through crafted HTTP requests targeting vulnerable endpoints, which validated RCE through repeated DNS lookups to confirm successful command execution. Evidence gathered during investigations indicated that attackers deployed webshells in directories associated with Tomcat web applications. Specifically, they targeted '403.jsp' to append malicious Base64-decoded Java bytecode, enabling in-memory class loader capabilities. Additionally, logs showed attempts to manipulate file permissions to enhance control over compromised environments. The presence of reverse shell attempts using tools like 'nc' and 'ncat' suggests they aimed for interactive access. Reports indicated activities related to loading secondary payloads, including a Base64-encoded ELF binary malware aimed at facilitating command and control operations. Specific database export commands targeting sensitive Ivanti user data signify attempts at credential harvesting, indicating a well-planned strategy for data exfiltration as well as lateral movement within affected networks. The challenges escalated as multiple actors engaged in opportunistic exploitation, creating a noisy threat landscape. They shifted from scanning for vulnerable devices to more sophisticated actions, including establishing dormant backdoors and deploying secondary malware, indicative of a persistent approach to maintain long-term access. Notably, reconnaissance activities were linked to commands injected to measure server vulnerabilities. As exploitation attempts rapidly spread across various sectors, particularly in the U.S., Germany, and Australia, security advisories called for immediate monitoring and response across networks, as organizations continued to face risks despite applying patches. Various indicators of compromise were associated with these threats, including altered file names typical of webshell deployment and suspicious data traffic. The BSI cautioned that even successfully patched systems should be considered compromised, advocating for broad network oversight to mitigate further risks stemming from these significant vulnerabilities.

    Post summary

    The report documents widespread, active exploitation of two critical Ivanti EPMM zero‑day CVEs, detailing Remote Code Execution via Bash scripts and reverse shell techniques, with confirmed real‑world attacks across multiple sectors and ongoing advisory efforts.

    0000062
    599 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager_mobile---

Explore more