Ivanti distributes two zero days that could lead to RCE in Endpoint Manager Mobile




  • Ivanti poured two defects that were chained to mount RCE attacks
  • A “limited number” of companies allegedly committed
  • Only the products are affected in the first

Ivanti has launched a patch for two vulnerabilities in its Mobile Software (EPMM) of Endpoint Manager, which is supposedly chained in the attacks of remote code execution (RCE) in nature.

Vulnerabilities are traced as CVE-2025-4427 and CVE-2025-4428. The first is an authentication bypass in the EPMM API, allowing threat actors to access protected resources. An average severity score of 5.3 was assigned.

Leave a Comment

Your email address will not be published. Required fields are marked *