Critical flaws in Ivanti EPMM lead to fast-moving exploitation attempts

Security researchers warn that the initial threat activity was highly targeted, as a limited number of users were impacted prior to disclosure.
Security teams are scrambling Tuesday as two critical vulnerabilities in Ivanti Endpoint Manager Mobile are facing exploitation attempts.
Health-ISAC pullout quotes:
The Health Information Sharing and Analysis Center (Health-ISAC) has identified a small number of organizations with potential exposure and has sent them targeted information with mitigation guidance, according to chief security officer Errol Weiss.
“This vulnerability is actively being exploited, and any organization using Ivanti EPMM should treat it as a high-priority patch and monitor it closely,” Weiss told Cybersecurity Dive. “Even when exposure is narrow, the systems involved are often critical to enterprise operations, so rapid remediation and heightened vigilance are essential.”
Read the article in Cybersecurity Dive. Click Here
- Related Resources & News
- Urgent Threat Alert: ShinyHunters Vishing Campaigns and Domain Impersonation
- When Everyone Can Find Your Bugs: Medical Device Security After AI
- AI Agents Are Changing Ransomware Attacks on Healthcare Organizations
- From Metrics to Meaning: Transforming Medical Device Cybersecurity into a Strategic Risk Narrative
- The Prioritization Problem: Why More Findings Don’t Mean Less Risk
- Monthly Newsletter – September 2026
- Health-ISAC ® Invests in APAC with Key Staff Addition in Australia
- Kidney Transplant Registry Hack Raises Safety Concerns
- Health-ISAC Hacking Healthcare 8-26-2026
- ShinyHunters Leaks 7.1 Million Baxter International Records