Skip to main content
Mallory
Back to intelligence
actively-exploited-vulnerabilitywidely-deployed-product-advisoryendpoint-software-vulnerabilityproof-of-concept-release

Ivanti and ConnectWise Patch Actively Exploited and Critical Enterprise Management Flaws

Updated 15d agoFirst seen May 4, 20266 sources

Ivanti released fixes for a newly disclosed high-severity flaw in its on-premises Endpoint Manager Mobile (EPMM) platform, tracked as CVE-2026-6973, after confirming limited zero-day exploitation. The vulnerability is caused by improper input validation and can lead to arbitrary code execution when a remote attacker already has administrator-level access. Ivanti said the issue affects EPMM 12.8.0.0 and earlier and issued patched versions 12.6.1.1, 12.7.0.1, and 12.8.0.1, while urging customers to review privileged accounts and rotate credentials. The disclosure adds to a longer pattern of Ivanti security incidents: CISA previously warned that CVE-2023-35082, a critical authentication bypass flaw in Ivanti EPMM and MobileIron Core, was being actively exploited to gain unauthenticated API access, expose user data, and potentially backdoor servers when chained with other vulnerabilities.

ConnectWise also disclosed a critical vulnerability in ConnectWise Automate, tracked as CVE-2026-9089, affecting versions prior to 2026.5. The flaw, classified as CWE-494, stems from insufficient integrity verification during plugin loading and self-update operations and could allow malicious code execution on client machines during agent updates under specific network conditions. ConnectWise assigned the issue a CVSS score of 8.8, automatically updated cloud deployments, and instructed on-premises customers to manually upgrade to version 2026.5; Canada’s Cyber Centre separately urged administrators to apply the vendor update. The disclosures highlight continued risk across widely deployed enterprise management platforms, with internet exposure data showing hundreds of Ivanti EPMM systems and broad operational dependence on remote monitoring and mobile device management software.

Share:
Ivanti and ConnectWise Patch Actively Exploited and Critical Enterprise Management Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
May 23, 202618d ago

Ivanti discloses four additional high-severity EPMM flaws

Alongside CVE-2026-6973, Ivanti disclosed four more high-severity vulnerabilities affecting EPMM. Ivanti said it had not observed active exploitation of those additional flaws.

Ivanti patches new EPMM zero-day CVE-2026-6973

Ivanti released security updates for CVE-2026-6973, a high-severity improper input validation flaw in on-premises EPMM that had seen limited zero-day exploitation. The company issued patched versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 and advised customers to review privileged accounts and rotate credentials.

May 21, 202620d ago

Canadian Centre for Cyber Security issues ConnectWise advisory

Canada's Cyber Centre published advisory AV26-496 urging administrators to review ConnectWise's security information and apply the ConnectWise Automate 2026.5 update. The notice highlighted that versions prior to 2026.5 are affected.

CVE record for ConnectWise Automate flaw is published

The CVE-2026-9089 record was published with a description, CWE-494 classification, CVSS details, and a vendor reference. The entry identified ConnectWise Automate 2026.5 as the remediation.

ConnectWise publishes advisory and fixes CVE-2026-9089 in Automate 2026.5

On May 21, 2026, ConnectWise disclosed CVE-2026-9089, a critical flaw in ConnectWise Automate involving insufficient integrity verification during plugin loading and self-update operations. The company said the issue affects versions prior to 2026.5, automatically updated cloud deployments, and required on-premises customers to upgrade manually.

Apr 20, 20262mo ago

ConnectWise releases Automate 2026.4 security fix bulletin

ConnectWise published a security bulletin for ConnectWise Automate 2026.4 on April 20, 2026. This is an earlier, separate vendor security update from the later 2026.5 bulletin tied to CVE-2026-9089.

ConnectWise Automate™ 2026.4 Security Fix | ConnectWise
Jan 18, 20242y ago

CISA warns CVE-2023-35082 is actively exploited

CISA said CVE-2023-35082 was under active exploitation and added it to the Known Exploited Vulnerabilities Catalog. The agency ordered U.S. federal civilian agencies to remediate affected systems by February 2, 2024 under Binding Operational Directive 22-01.

Aug 1, 20233y ago

Ivanti patches CVE-2023-35082 in EPMM and MobileIron Core

Ivanti released fixes for CVE-2023-35082 in August 2023. The vulnerability could also help attackers backdoor compromised servers when chained with other flaws.

Rapid7 reports Ivanti EPMM auth bypass flaw to Ivanti

Rapid7 discovered and reported CVE-2023-35082, a critical authentication bypass vulnerability affecting Ivanti Endpoint Manager Mobile and MobileIron Core. The flaw allows unauthenticated remote API access and exposure of mobile users' personally identifiable information.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Ivanti and ConnectWise Patch Actively Exploited and Critical Enterprise Management Flaws | Mallory