Ivanti EPMM RCE Vulnerability Chain Exploited in the Wild
ID: 7ff0f37e-c366-50ff-8c78-1c2f6c81f962
STIX ID: report--7ff0f37e-c366-50ff-8c78-1c2f6c81f962
Feed Name: Wiz Blog
Threat Score
On May 13, 2025 Ivanti disclosed two EPMM vulnerabilities (CVE-2025-4427 and CVE-2025-4428) that, when chained, enable unauthenticated remote code execution; Wiz observed active exploitation starting May 16, 2025 deploying Sliver beacons, JSP web shells, MySQL dumps, and reverse shells, provided numerous IOCs (file hashes, IPs, domains), and recommended patching to specific fixed EPMM versions and applying network restrictions to vulnerable endpoints.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
