Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityinternet-facing-service-vulnerabilityproof-of-concept-releasedata-exfiltration-method

Ivanti EPMM Zero-Day Exploitation Exposed Sensitive Government and Enterprise Data

Updated 29d agoFirst seen Mar 27, 202610 sources

Ivanti warned that two critical zero-day flaws in Endpoint Manager Mobile (EPMM)CVE-2026-1281 and CVE-2026-1340 — were being actively exploited, and subsequent reporting described rapid mass exploitation after proof-of-concept code became public. The attacks hit internet-facing EPMM systems used to manage mobile devices, with incident responders documenting a fully automated intrusion chain that successfully exfiltrated sensitive EPMM data and leveraged lesser-known product behaviors alongside an open-source offensive framework. Germany's BSI also issued an alert on active attacks, underscoring the broad operational impact of the campaign.

The exploitation wave affected both opportunistic victims and targeted organizations, including governments. Dutch authorities disclosed that attackers had maintained access to the Dutch Custodial Institutions Agency's EPMM server for about five months, exposing employee names, email addresses, phone numbers, and location data, with officials warning of elevated blackmail and extortion risks. Ivanti's earlier handling of EPMM flaws, including CVE-2023-35082, had already shown that internet-exposed deployments could enable unauthorized access to personally identifiable information, but the company separately clarified that a later May 2026 advisory for Endpoint Manager (EPM) — covering CVE-2026-8109, CVE-2026-8110, and CVE-2026-8111 — involved a different product and was not tied to the EPMM zero-day exploitation.

Share:
Ivanti EPMM Zero-Day Exploitation Exposed Sensitive Government and Enterprise Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
May 12, 20261mo ago

Ivanti releases fixes for three Endpoint Manager vulnerabilities

Ivanti published a security advisory for Endpoint Manager (EPM) covering CVE-2026-8109, CVE-2026-8110, and CVE-2026-8111, affecting EPM 2024 SU5 and earlier. The company fixed the issues in Endpoint Manager 2024 SU6 and said it was not aware of customer exploitation before public disclosure, while clarifying these flaws affected EPM rather than EPMM.

Apr 14, 20262mo ago

DJI implements response measures while forensic investigation continues

Following the confirmed breach, DJI deployed technical and monitoring measures, distributed a response plan to employees, and used National Cyber Security Centre recommendations. Authorities said a full forensic investigation and cause analysis were still underway, with concerns about blackmail and extortion risks to staff.

Dutch government confirms breach of DJI Ivanti EPMM server

State Secretary of Justice and Security Van Bruggen confirmed that the Dutch Custodial Institutions Agency (DJI) suffered a breach involving its Ivanti EPMM server. Attackers were found to have maintained access for five months, and exposed data included employee names, email addresses, phone numbers, and location data.

Feb 13, 20264mo ago

Germany's BSI warns of active zero-day attacks on Ivanti EPMM

Germany's Federal Office for Information Security (BSI) issued a cyber warning stating that active attacks exploiting Ivanti EPMM zero-day vulnerabilities had been observed. The alert reflected escalating official concern over ongoing exploitation.

Feb 10, 20264mo ago

Incident responders confirm automated data exfiltration in an EPMM breach

In one investigated compromise, an incident response team confirmed attackers used a fully automated and carefully prepared attack chain to exfiltrate sensitive EPMM data. The report also noted lesser-known technical details and a link to an open-source offensive framework.

Jan 30, 20265mo ago

Mass exploitation of Ivanti EPMM begins

After the proof-of-concept became public, attackers began broad exploitation of vulnerable Ivanti EPMM systems. Reporting described both opportunistic actors and more targeted operators pursuing specific objectives, including governments and other organizations.

Jan 29, 20265mo ago

Proof-of-concept exploit for the EPMM flaws is published

A proof-of-concept exploit for the two critical Ivanti EPMM remote code execution vulnerabilities was published in late January 2026. Subsequent reporting tied this release to a rapid increase in attacker activity.

Ivanti warns of two zero-day EPMM vulnerabilities under active exploitation

Ivanti published a security advisory for Ivanti Endpoint Manager Mobile covering CVE-2026-1281 and CVE-2026-1340, warning that the flaws were being exploited as zero-days. This marked the public disclosure of the two critical EPMM issues.

Aug 21, 20233y ago

Ivanti releases patch for CVE-2023-35082 in EPMM 11.11.0.0

Ivanti said CVE-2023-35082 was patched in EPMM version 11.11.0.0 and recommended network mitigations such as restricting exposed ports because exploitation was possible over HTTP but not HTTPS. The company also noted some customers were exploited after Rapid7 publicly disclosed details and that additional exploitation paths depended on appliance configuration.

Aug 7, 20233y ago

Ivanti discloses CVE-2023-35082 in EPMM and MobileIron Core

Ivanti disclosed the remote unauthenticated API access vulnerability CVE-2023-35082 affecting Ivanti Endpoint Manager Mobile (EPMM) 11.10, 11.9, 11.8 and MobileIron Core 11.7 and below. The flaw could let an internet-facing unauthenticated attacker access users’ personally identifiable information and make limited server changes.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

3 LINKEDOpen in app
Affected products
1 linked
Endpoint Manager Mobile
Organizations
2 linked
IvantiBasic-Fit
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.