National CERT Issues Critical Alert on Ivanti Mobile System Vulnerabilities
Pakistan’s National Computer Emergency Response Team (CERT) has issued a high-severity advisory warning of active attacks targeting Ivanti Endpoint Manager Mobile systems. The advisory highlights critical zero-day vulnerabilities in on-premises deployments that are currently being exploited in the wild.
According to the advisory, these vulnerabilities allow attackers to execute malicious code remotely without authentication, potentially giving them full control over affected systems. Ivanti has confirmed the security flaws, and one of the vulnerabilities has been listed in the Known Exploited Vulnerabilities catalogue maintained by the Cybersecurity and Infrastructure Security Agency (CISA), indicating active exploitation globally.
National CERT rated the vulnerabilities with a critical CVSS score of 9.8, emphasizing the serious threat they pose to system confidentiality, integrity, and availability. Successful attacks could expose sensitive mobile device data, disrupt enterprise mobile management operations, and even provide a pathway into broader government or corporate networks.
Organizations using Ivanti Endpoint Manager Mobile are urged to apply patches immediately, implement mitigation strategies, and review system logs for unusual activity. The CERT also recommends increasing monitoring of network traffic and restricting administrative access until the vulnerabilities are fully addressed.
The advisory underscores the growing cybersecurity threats targeting mobile management systems and highlights the need for rapid response to safeguard sensitive data across enterprise and government infrastructures.


