Skip to content
COOEY

FAIL › dossier

Endpoint Manager Mobile (EPMM)

PRODUCT

· dossier confidence 0%

Ivanti Endpoint Manager Mobile (EPMM) has been repeatedly targeted by attackers, including Chinese state-sponsored groups (UNC5221), due to critical vulnerabilities like unauthenticated remote code execution and authentication bypass. These flaws have led to breaches of government agencies and organizations globally, highlighting a persistent and serious security risk.

PROFILE
CategoryEndpoint ManagementWhat they doIvanti Endpoint Manager Mobile (EPMM) provides mobile device management (MDM) and unified endpoint management (UEM) solutions. It enables organizations to manage and secure mobile devices and endpoints.
SECURITY POSTURE

Ivanti EPMM has demonstrated a consistently poor security posture, with numerous critical and high-severity vulnerabilities exploited in the wild. These vulnerabilities frequently involve remote code execution and authentication bypass, indicating significant weaknesses in the product's design and implementation.

Notable failures
  • CVE-2026-1340: Unauthenticated RCE via code injection
  • CVE-2023-35078: Authentication bypass allowing PII access
  • CVE-2026-6973: RCE for authenticated admins via improper input validation
  • CVE-2026-1281: Unauthenticated RCE via code injection
  • CVE-2025-4428: RCE via API component
  • CVE-2025-4427: Authentication bypass in API component
Patterns: Repeated unpatched remote code execution (RCE) vulnerabilities; Authentication bypass vulnerabilities; Vulnerabilities in API components; Improper input validation leading to RCE
FAILURE HISTORY · 7
DATEEVENTSEVSUMMARY
2026-01-29 CVE-2026-1281 high Ivanti EPMM exposed to unauthenticated RCE due to code injection flaw
2026-04-08 CVE-2026-1340 high Ivanti EPMM allows unauthenticated remote code execution via code injection, enabling attackers to compromise endpoint management systems without credentials.
2023-07-25 CVE-2023-35078 critical Ivanti Endpoint Manager Mobile suffered an authentication bypass allowing unauthenticated access to PII and device configuration.
2025-05-19 CVE-2025-4428 high Ivanti EPMM API code injection allows remote execution of arbitrary code by authenticated attackers
2025-05-19 CVE-2025-4427 high Ivanti EPMM API flaw allows unauthorized access via crafted requests
2023-07-31 CVE-2023-35081 high An authenticated administrator of Ivanti Endpoint Manager Mobile (EPMM) can write malicious files to the server via a path traversal vulnerability, potentially bypassing access controls and enabling further compromise.
2026-05-07 CVE-2026-6973 high Ivanti EPMM allows remote code execution for authenticated admins via improper input validation.
Open questions: What is the current patching status of EPMM deployments? · What is Ivanti's remediation plan for past vulnerabilities?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-21 06:11:16.894059+00:00