Federal cybersecurity regulators have issued an emergency addition to the Known Exploited Vulnerabilities catalog, mandating immediate patching for an enterprise mobile management platform. The vulnerability permits remote unauthenticated network actors to bypass access controls and execute operating system commands on underlying server appliances.
The security flaw, tracked as CVE-2026-35051 with a CVSS score of 9.8, impacts Ivanti Endpoint Manager Mobile EPMM installations. The defect resides in an exposed API routing service that fails to validate incoming user tokens. Unauthenticated adversaries issue crafted HTTP requests to bypass authentication layers, spawning root shell processes and establishing persistent backdoors. Due to verified wild exploitation targeting government and commercial networks, CISA added the flaw to the KEV database under Binding Operational Directive 26-04.
Subverting a centralized mobile device management platform compromises enterprise mobile fleets. Because MDM appliances hold device management certificates, corporate network profiles, and mobile access tokens, an unauthenticated takeover allows threat actors to push malicious software profiles to enrolled mobile devices and pivot into internal corporate networks.
– Force immediate installation of security hotfix build 12.2.0.3 across all Ivanti EPMM deployment servers.
– Restrict public internet exposure of EPMM administrative web portals, gating visibility behind zero trust access gateways.
– Inspect server application logs for anomalous HTTP requests targeting internal API routing handlers.
– Audit enrolled mobile device configurations for unauthorized profile installations or unverified certificate additions.
Enterprise mobile infrastructure defense demands rapid security patching paired with strict perimeter interface controls to ensure centralized management platforms remain shielded from unauthenticated access manipulation. #CodeDefence #Ivanti #EPMM #AuthBypass #MDM #CISA #KEV #MobileSecurity
/
