China-linked APT UNC5221 started exploiting Ivanti EPMM flaws shortly after their disclosureSecurity Affairs·May 26, 11:31 UTC · May 26, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-442860
Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates ReleasedThe Hacker News·Apr 9, 04:57 UTC · Apr 9, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-134060
Chinese cyber spies are using Ivanti EPMM flaws to breach EU, US organizationsHelp Net Security·May 23, 00:00 UTC · May 23, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-442860
PoC exploit for Ivanti EPMM privilege escalation flaw released (CVE 2024-22026)Help Net Security·May 20, 00:00 UTC · May 20, 2024Exploit / PoCCVE-2024-22026CVE-2023-46806CVE-2023-4680760
Ivanti EPMM vulnerabilities exploited in the wild (CVE-2025-4427, CVE-2025-4428)Help Net Security·May 16, 13:18 UTC · May 16, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-4428CVE-2025-22462+1 CVEs60
Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network AttacksThe Hacker News·May 22, 12:07 UTC · May 22, 2025Exploit / PoCCVE-2025-4427CVE-2025-4428CVE-2025-3132460
U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 30, 10:40 UTC · Jan 30, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-2485860
U.S. CISA adds a flaw in Ivanti EPMM to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 8, 21:35 UTC · Apr 8, 2026Exploit / PoC in the wildCVE-2026-134060
U.S. CISA adds Ivanti EPMM, MDaemon Email Server, Srimax Output Messenger, Zimbra Collaboration, and ZKTeco BioTime flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 21, 10:14 UTC · May 21, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-4428CVE-2024-11182+3 CVEs60
83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting InfrastructureThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-1340CVE-2026-21962+2 CVEs60
Ivanti’s EPMM is under active attack, thanks to two critical zeroCyberScoop·Feb 4, 15:22 UTC · Feb 4, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-1340CVE-2025-442860
Fallout from latest Ivanti zeroCyberScoop·Feb 10, 00:03 UTC · Feb 10, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-134060
Ivanti EPMM vulnerability exploited in zero-day attacks (CVE-2026-6973)Help Net Security·May 8, 00:00 UTC · May 8, 2026Exploit / PoC in the wildCVE-2026-6973CVE-2026-1281CVE-2026-1340+4 CVEs60
CISA adds Ivanti EPMM flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jul 26, 11:53 UTC · Jul 26, 2023Exploit / PoC in the wildCVE-2023-3507860
CISA adds second Ivanti EPMM flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Aug 2, 06:01 UTC · Aug 2, 2023Exploit / PoC in the wildCVE-2023-35081CVE-2023-3507860
Ivanti customers confront yet another actively exploited zeroCyberScoop·May 7, 21:50 UTC · May 7, 2026Exploit / PoC in the wildCVE-2026-6973CVE-2026-5787CVE-2026-5788+3 CVEs60
Ivanti provides temporary patches for actively exploited EPMM zero-day (CVE-2026-1281)Help Net Security·Feb 2, 10:44 UTC · Feb 2, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-134060
U.S. CISA adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 7, 18:03 UTC · May 7, 2026Exploit / PoC in the wildCVE-2026-697360
Ivanti Releases Urgent Patch for EPMM Zero-Day Vulnerability Under Active ExploitationThe Hacker News·Jul 26, 04:20 UTC · Jul 26, 2023Exploit / PoC in the wildCVE-2023-3507860
Week in review: Google fixes yet another Chrome zero-day exploit, YouTube as a cybercrime channelHelp Net Security·May 26, 00:00 UTC · May 26, 2024Exploit / PoC in the wildCVE-2024-5274CVE-2024-4985CVE-2023-43208+4 CVEs60
Ivanti Sentry zero-day vulnerability exploited, patch ASAP! (CVE-2023-38035)Help Net Security·Aug 24, 12:34 UTC · Aug 24, 2023Exploit / PoC in the wildCVE-2023-3803560
Ivanti: Customers ‘impacted’ by new zeroThe Record·Aug 21, 18:55 UTC · Aug 21, 2023Exploit / PoCCVE-2023-3803560
Ivanti Warns of Critical Zero-Day Flaw Being Actively Exploited in Sentry SoftwareThe Hacker News·Aug 25, 06:25 UTC · Aug 25, 2023Exploit / PoC in the wildCVE-2023-38035CVE-2023-35078CVE-2023-35081+2 CVEs60
Ivanti zero-day exploited to target Norwegian government (CVE-2023-35078)Help Net Security·Jul 31, 13:19 UTC · Jul 31, 2023Exploit / PoC in the wildCVE-2023-3507860
EU, Dutch government announce hacks following Ivanti zeroThe Record·Feb 9, 13:31 UTC · Feb 9, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-134060
Week in review: 10 cybersecurity frameworks you need to know, exploited Chrome zero-day fixedHelp Net Security·Jan 21, 00:00 UTC · Jan 21, 2024Exploit / PoC in the wildCVE-2023-36025CVE-2023-22527CVE-2024-0519+3 CVEs60
Dutch Authorities Confirm Ivanti Zero-Day Exploit Exposed Employee Contact DataThe Hacker News·Feb 12, 05:21 UTC · Feb 12, 2026Exploit / PoCCVE-2026-1281CVE-2026-134060
Ivanti: Three CSA ZeroInfosecurity Magazine·Oct 9, 10:15 UTC · Oct 9, 2024Exploit / PoC in the wildCVE-2024-9379CVE-2024-9380CVE-2024-9381+2 CVEs60
New flaw in Ivanti Endpoint Manager Mobile actively exploited in the wildSecurity Affairs·Jul 30, 12:47 UTC · Jul 30, 2023Exploit / PoC in the wildCVE-2023-35081CVE-2023-3507860
⚡ Weekly Recap: Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New ThreatsThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-1281CVE-2026-134060
U.S. CISA adds a Samsung MagicINFO 9 Server flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 22, 22:17 UTC · May 22, 2025Exploit / PoC in the wildCVE-2025-463260
Week in review: Microsoft fixes exploited Office zero-day, Fortinet patches FortiCloud SSO flawHelp Net Security·Feb 1, 00:00 UTC · Feb 1, 2026Exploit / PoC in the wildCVE-2026-21509CVE-2026-24858CVE-2025-8088+1 CVEs60
Ivanti enhances its solutions portfolio to drive secure, scalable, and streamlined IT operationsHelp Net Security·Oct 22, 00:00 UTC · Oct 22, 2025Exploit / PoC60
May 2026 CVE LandscapeRecorded Future·Jun 15, 00:00 UTC · Jun 15, 2026Exploit / PoC in the wildCVE-2008-4250CVE-2009-1537CVE-2009-3459+19 CVEs60
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent AccessThe Hacker News·Jul 23, 06:05 UTC · Jul 23, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-4428CVE-2025-53770+3 CVEs60
Week in review: Ivanti zero-day exploited, MikroTik vulnerability could compromise 900,000 routersHelp Net Security·Aug 13, 19:33 UTC · Aug 13, 2023Exploit / PoCCVE-2023-30799CVE-2023-35078CVE-2023-3860660
Two Ivanti ZeroInfosecurity Magazine·Jan 11, 09:30 UTC · Jan 11, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2023-35078+1 CVEs60
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14Security Affairs·Jun 14, 13:16 UTC · Jun 14, 2026Exploit / PoC in the wildCVE-2026-1052060