logo

Ivanti EPMM RCE Vulnerability Chain Exploited in the Wild (Campaign)

ID: 709a7914-d433-549d-b63f-85c8e4f8ff08

STIX ID: report--709a7914-d433-549d-b63f-85c8e4f8ff08

Feed Name: Wiz Cloud Threat Landscape

Threat Score
85/100

Date Published: 2025-05-20

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Wiz Threat Research confirmed active exploitation of a chained Ivanti EPMM vulnerability (CVE-2025-4427 + CVE-2025-4428) that enables unauthenticated remote code execution due to unsafe Java Expression Language use and misconfigured Spring Security. Exploitation began shortly after public disclosure and PoC release; observed post-exploitation activity includes Sliver C2 beaconing, MySQL database dumping, web shells disguised as files like 401.jsp and css.css, and reverse/fileless shells, affecting EPMM versions 11.12.0.4, 12.3.0.1, 12.4.0.1, 12.5.0.0 and earlier.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.