Two chained zero-day vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) are being actively exploited in the wild, enabling attackers to achieve unauthenticated remote code execution on exposed Mobile Device Management (MDM) servers. The flaws allow threat actors to deploy web shells, cryptominers, and persistent backdoors — effectively granting them full control over the mobile device fleets managed by compromised servers.

The attack chain is particularly dangerous because MDM platforms are, by design, trusted by every device they manage. Once an attacker controls the MDM server, they can push malicious configurations, install surveillance tools, or wipe devices across an entire organization. Ivanti has released emergency patches, but the window of exploitation appears to have been open for an indeterminate period before discovery.

Source

Reported by The Hacker News and Help Net Security on April 10, 2026.

Commentary

Ivanti keeps finding itself at the center of zero-day storms, and at this point the pattern is hard to ignore. EPMM, Connect Secure, Policy Secure — the company’s security product portfolio has become a recurring source of critical vulnerabilities. For an MDM vendor, a pre-auth RCE chain is about as bad as it gets: attackers don’t just compromise one system, they inherit trusted access to every device the platform manages.

If your organization runs Ivanti EPMM, treat this as a drop-everything priority. Patch immediately, audit your MDM server logs for indicators of compromise, and seriously evaluate whether your MDM attack surface is appropriately segmented from the rest of your network. The broader lesson: the tools we use to manage security are themselves high-value targets, and they need to be secured accordingly.

By Allan