Ivanti fixes EPMM zero-days chained in code execution attacks
ID: fbd63485-8c34-58ac-b637-352580586808
STIX ID: report--fbd63485-8c34-58ac-b637-352580586808
Feed Name: Bleeping Computer
Threat Score
Ivanti issued advisories and patches for two vulnerabilities in its on-prem Endpoint Manager Mobile (EPMM) product — CVE-2025-4427 (authentication bypass) and CVE-2025-4428 (remote code execution) — which when chained can allow unauthenticated remote code execution. The vendor released specific patched versions and urged customers to apply updates; Ivanti reported a very limited number of known exploitations while Shadowserver notes hundreds of EPMM instances exposed online.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
