Vulnary
← back to the feed
Critical· 9.8actively exploited

CVE-2023-35078

CVE-2023-35078 is a critical authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that lets unauthenticated attackers access restricted functions or data. It has a CVSS score of 9.8 and is known exploitation. CISA advises applying vendor-provided mitigations or discontinuing use of the product if mitigations are not available.

publishedJul 25, 2023
last modifiedAug 5, 2026
sourcesNVD · CISA-KEV
severity · cvss
9.8
critical · how bad it is
exploitation · epss
100%
100th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 19, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Ivanti Endpoint Manager Mobile (EPMM)

02

Real-world impact

Unauthorized access to sensitive application functionality and data, potentially leading to full compromise.

03

Why this severity

CVSS 9.8 (Critical) reflects network‑reachable, low‑complexity attack with no privileges or user interaction required, impacting confidentiality, integrity, and availability.

04

What to do about it

no official fix yet
interim mitigations
  • Apply mitigations per Ivanti vendor instructions.
  • If mitigations cannot be applied, discontinue use of Ivanti EPMM.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

CISA KEV required action

05

Timeline

  1. Jul 25, 2023 · Jul 25, 2023
    Confirmed exploited (CISA KEV)
    CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
  2. Jul 25, 2023 · Jul 25, 2023
    Published
    Disclosed and added to the National Vulnerability Database.
  3. Aug 15, 2023 · Aug 15, 2023
    CISA remediation deadline
    Federal agencies are required to remediate by this date.
  4. Aug 5, 2026 · 1d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →