logo

Ivanti EPMM RCE Vulnerability Chain Exploited in the Wild

ID: 7ff0f37e-c366-50ff-8c78-1c2f6c81f962

STIX ID: report--7ff0f37e-c366-50ff-8c78-1c2f6c81f962

Feed Name: Wiz Blog

Threat Score
85/100

Date Published: 2025-05-20

Date Updated: 2026-05-01

...
...

On May 13, 2025 Ivanti disclosed two EPMM vulnerabilities (CVE-2025-4427 and CVE-2025-4428) that, when chained, enable unauthenticated remote code execution; Wiz observed active exploitation starting May 16, 2025 deploying Sliver beacons, JSP web shells, MySQL dumps, and reverse shells, provided numerous IOCs (file hashes, IPs, domains), and recommended patching to specific fixed EPMM versions and applying network restrictions to vulnerable endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.