
🧠 Technical Analysis of CVE-2025-4427/4428: Ivanti EPMM Remote Code Execution Writeup: https://httpvoid.com/Ivanti-EPMM-Remote-Code-Execution.md Author: @httpvoid0x2f https://t.co/K1OjLEtAFT
Exploitation ongoing with high activity in latest observed window (1 mentions)
Recommended action window: Immediate (within 24h)
NVD description
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-09. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Priority
MEDIUM
Exploitation
ACTIVE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
1 version affected across 1 product

🧠 Technical Analysis of CVE-2025-4427/4428: Ivanti EPMM Remote Code Execution Writeup: https://httpvoid.com/Ivanti-EPMM-Remote-Code-Execution.md Author: @httpvoid0x2f https://t.co/K1OjLEtAFT

🚨 In this week’s Threat Alert, we cover CVE-2025-4427, an authentication bypass in Ivanti Endpoint Manager Mobile (EPMM) that can be chained with CVE-2025-4428 for unauthenticated remote code execution. CrowdSec has observed 865 unique IP addresses sending requests matching the exploitation pattern since May 2025. Read our latest article for the full analysis, protection recommendations, and more: https://www.crowdsec.net/vulntracking-report/ivanti-epmm-cve-2025-4427-authentication-bypass Keep your network informed. Like and share this post!
Post summary
The text reports active exploitation of CVE-2025-4427 and CVE-2025-4428 by 865 unique IPs observed since May 2025, with technical details of the authentication bypass and RCE chain disclosed.

Imagine patching a critical zero-day the same day it drops. You feel great. Except the attacker got in last week, and they're not on that appliance anymore. (Joke on you.) That's what our IR team at Profero saw in multiple Ivanti EPMM cases in 2025 (CVE-2025-4427 and CVE-2025-4428). In several engagements, attackers had already moved laterally and set up persistence before the appliance was isolated. Patching closes the door. It doesn't tell you who already walked through it. Honest question: after you patch an edge device, do you hunt for what's already inside, or move on to the next fire? Our live forensic collection guide is in the first comment>>>

We wrote up exactly how we ran live forensic collection against compromised Ivanti EPMM appliances during CVE-2025-4427 and CVE-2025-4428. If you're running EPMM and haven't patched, this is your prompt. If you already have, it's still worth reading for the collection method alone. https://profero.io/blog/ivanti-epmm-attacks/ What are your thoughts on this one?
Post summary
The post reports real‑world compromise of Ivanti EPMM appliances via CVE-2025-4427 and CVE-2025-4428, shares forensic collection methods, and urges prompt patching.

Ivanti EPMM users urgently need to patch against actively exploited 0day vulnerabilities (CVE-2025-4427, CVE-2025-4428) that enable pre-authenticated remote… https://f.mtr.cool/tljzmncqkb
Post summary
The post warns Ivanti EPMM users that CVE-2025-4427 and CVE-2025-4428 are actively exploited zero‑day vulnerabilities, urging immediate patching.
2 of 2 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | ivanti | endpoint_manager_mobile | - | - | - |
| App | ivanti | endpoint_manager_mobile | 12.5.0.0 | - | - |