Ivanti Endpoint Manager Mobile (EPMM) known exploited vulnerabilities, ranked
CISA lists 7 Ivanti Endpoint Manager Mobile (EPMM) CVEs as exploited in the wild. 3 were added in the last 12 months and 1 are known to be used in ransomware. The table ranks all of them by EPSS, FIRST's estimate of the chance a CVE is exploited in the next 30 days, so the first rows are the ones to patch first.
Patch these first
- CVE-2023-35078: EPSS 100.00%, used in ransomware, added 2023-07-25
- CVE-2025-4427: EPSS 99.93%, added 2025-05-19
- CVE-2026-1281: EPSS 98.7%, added 2026-01-29
- CVE-2026-1340: EPSS 98.6%, added 2026-04-08
- CVE-2025-4428: EPSS 86.5%, added 2025-05-19
All 7 Ivanti Endpoint Manager Mobile (EPMM) CVEs in CISA KEV, by EPSS
| # | CVE | Flaw | EPSS | Ransomware | Added | Federal due |
|---|---|---|---|---|---|---|
| 1 | CVE-2023-35078 | Endpoint Manager Mobile Authentication Bypass | 100.00% | Yes | 2023-07-25 | 2023-08-15 |
| 2 | CVE-2025-4427 | Endpoint Manager Mobile (EPMM) Authentication Bypass | 99.93% | – | 2025-05-19 | 2025-06-09 |
| 3 | CVE-2026-1281 | Endpoint Manager Mobile (EPMM) Code Injection | 98.7% | – | 2026-01-29 | 2026-02-01 |
| 4 | CVE-2026-1340 | Endpoint Manager Mobile (EPMM) Code Injection | 98.6% | – | 2026-04-08 | 2026-04-11 |
| 5 | CVE-2025-4428 | Endpoint Manager Mobile (EPMM) Code Injection | 86.5% | – | 2025-05-19 | 2025-06-09 |
| 6 | CVE-2023-35081 | Endpoint Manager Mobile (EPMM) Path Traversal | 63.6% | – | 2023-07-31 | 2023-08-21 |
| 7 | CVE-2026-6973 | Endpoint Manager Mobile (EPMM) Improper Input Validation | 2.5% | – | 2026-05-07 | 2026-05-10 |
EPSS changes daily; a CVE with a low EPSS that is in KEV is still exploited somewhere. Federal due dates bind US federal civilian agencies; everyone else can use them as a priority hint.
Sources: CISA KEV, FIRST EPSS.
More: all Ivanti KEV CVEs · other Ivanti products: Pulse Connect Secure · free KEV badge for Ivanti · all vendors