CVE-2025-4427Active Exploitation(ivanti / endpoint_manager_mobile)

MEDIUMCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch ivanti endpoint_manager_mobile systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-09. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-288

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager_mobile

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 4d ago at 1 mentions (2026-05-18); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
endpoint_manager_mobile

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-05-18: 1Mentions · 2026-08-11: 1Mentions · 2026-09-21: 1Mentions · 2026-10-02: 1Mentions · 2026-10-05: 1Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-08-11: 1Active Exploitation · 2026-09-21: 1Patch / Workaround · 2026-08-11: 1Technical Details · 2026-09-21: 105-1808-1109-2110-0210-05
Signal classification1 categories
Active Exploitation
3100.0%
Referenced assets4 URLs
Full discourse5 posts
  • Muqsit 𝕏@mqst_

    🧠 Technical Analysis of CVE-2025-4427/4428: Ivanti EPMM Remote Code Execution Writeup: https://httpvoid.com/Ivanti-EPMM-Remote-Code-Execution.md Author: @httpvoid0x2f https://t.co/K1OjLEtAFT

    04059302.6K
    13.3K followersView on X
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 In this week’s Threat Alert, we cover CVE-2025-4427, an authentication bypass in Ivanti Endpoint Manager Mobile (EPMM) that can be chained with CVE-2025-4428 for unauthenticated remote code execution. CrowdSec has observed 865 unique IP addresses sending requests matching the exploitation pattern since May 2025. Read our latest article for the full analysis, protection recommendations, and more: https://www.crowdsec.net/vulntracking-report/ivanti-epmm-cve-2025-4427-authentication-bypass Keep your network informed. Like and share this post!

    Post summary

    The text reports active exploitation of CVE-2025-4427 and CVE-2025-4428 by 865 unique IPs observed since May 2025, with technical details of the authentication bypass and RCE chain disclosed.

    00050593
    19.4K followersView on X
  • Profero@ProferoSec

    Imagine patching a critical zero-day the same day it drops. You feel great. Except the attacker got in last week, and they're not on that appliance anymore. (Joke on you.) That's what our IR team at Profero saw in multiple Ivanti EPMM cases in 2025 (CVE-2025-4427 and CVE-2025-4428). In several engagements, attackers had already moved laterally and set up persistence before the appliance was isolated. Patching closes the door. It doesn't tell you who already walked through it. Honest question: after you patch an edge device, do you hunt for what's already inside, or move on to the next fire? Our live forensic collection guide is in the first comment>>>

    10010145
    1.6K followersView on X
  • Profero@ProferoSec
    Active Exploitation

    We wrote up exactly how we ran live forensic collection against compromised Ivanti EPMM appliances during CVE-2025-4427 and CVE-2025-4428. If you're running EPMM and haven't patched, this is your prompt. If you already have, it's still worth reading for the collection method alone. https://profero.io/blog/ivanti-epmm-attacks/ What are your thoughts on this one?

    Post summary

    The post reports real‑world compromise of Ivanti EPMM appliances via CVE-2025-4427 and CVE-2025-4428, shares forensic collection methods, and urges prompt patching.

    00020161
    1.6K followersView on X
  • @pedri77@pedri77
    Active Exploitation

    Ivanti EPMM users urgently need to patch against actively exploited 0day vulnerabilities (CVE-2025-4427, CVE-2025-4428) that enable pre-authenticated remote… https://f.mtr.cool/tljzmncqkb

    Post summary

    The post warns Ivanti EPMM users that CVE-2025-4427 and CVE-2025-4428 are actively exploited zero‑day vulnerabilities, urging immediate patching.

    000001.2K
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager_mobile---
Appivantiendpoint_manager_mobile12.5.0.0--

Explore more