Ivanti EPMM Bugs Combine for Unauthenticated RCE in the Wild
ID: c8bb48ff-0b58-5460-9ae4-8add97e54383
STIX ID: report--c8bb48ff-0b58-5460-9ae4-8add97e54383
Feed Name: Kudelski Security
Threat Score
Ivanti disclosed two EPMM vulnerabilities (CVE-2025-4427 auth bypass and CVE-2025-4428 EL-injection RCE) which, when chained, allow unauthenticated remote code execution; limited in-the-wild exploitation beginning mid‑May has been observed and linked to post‑exploitation Sliver implants and active C2 infrastructure, with affected versions and patches listed plus interim network mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
