CVE-2025-4428Active Exploitation(ivanti / endpoint_manager_mobile)

MEDIUMCVSS 8.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch ivanti endpoint_manager_mobile systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-09. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager_mobile

Threat summary

  • Active exploitation appears in 3 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Peaked 3d ago at 1 mentions (2026-05-18); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
endpoint_manager_mobile

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-18: 1Mentions · 2026-08-11: 1Mentions · 2026-09-21: 1Mentions · 2026-10-05: 1Active Exploitation · 2026-05-18: 1Active Exploitation · 2026-08-11: 1Active Exploitation · 2026-09-21: 1Patch / Workaround · 2026-05-18: 1Technical Details · 2026-09-21: 105-1808-1109-2110-05
Signal classification2 categories
Active Exploitation
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-181
Patch1
2026-08-111
Active Exploitation1
2026-09-211
Active Exploitation1
Full discourse4 posts
  • CrowdSec@Crowd_Security
    Active Exploitation

    🚨 In this week’s Threat Alert, we cover CVE-2025-4427, an authentication bypass in Ivanti Endpoint Manager Mobile (EPMM) that can be chained with CVE-2025-4428 for unauthenticated remote code execution. CrowdSec has observed 865 unique IP addresses sending requests matching the exploitation pattern since May 2025. Read our latest article for the full analysis, protection recommendations, and more: https://www.crowdsec.net/vulntracking-report/ivanti-epmm-cve-2025-4427-authentication-bypass Keep your network informed. Like and share this post!

    Post summary

    The alert details CVE‑2025‑4427 as an authentication bypass in Ivanti EPMM that can be combined with CVE‑2025‑4428 for unauthenticated RCE, and CrowdSec reports 865 unique IPs have been observed exploiting it, confirming active in‑the‑wild exploitation.

    00050595
    19.4K followersView on X
  • Profero@ProferoSec

    Imagine patching a critical zero-day the same day it drops. You feel great. Except the attacker got in last week, and they're not on that appliance anymore. (Joke on you.) That's what our IR team at Profero saw in multiple Ivanti EPMM cases in 2025 (CVE-2025-4427 and CVE-2025-4428). In several engagements, attackers had already moved laterally and set up persistence before the appliance was isolated. Patching closes the door. It doesn't tell you who already walked through it. Honest question: after you patch an edge device, do you hunt for what's already inside, or move on to the next fire? Our live forensic collection guide is in the first comment>>>

    10010150
    1.6K followersView on X
  • Profero@ProferoSec
    Active Exploitation

    We wrote up exactly how we ran live forensic collection against compromised Ivanti EPMM appliances during CVE-2025-4427 and CVE-2025-4428. If you're running EPMM and haven't patched, this is your prompt. If you already have, it's still worth reading for the collection method alone. https://profero.io/blog/ivanti-epmm-attacks/ What are your thoughts on this one?

    Post summary

    The post confirms that CVE‑2025‑4427 and CVE‑2025‑4428 are actively exploited against Ivanti EPMM appliances, highlighting a forensic collection approach, though it lacks details on PoC, exploit code, or patch information.

    00020161
    1.6K followersView on X
  • @pedri77@pedri77
    Patch

    Ivanti EPMM users urgently need to patch against actively exploited 0day vulnerabilities (CVE-2025-4427, CVE-2025-4428) that enable pre-authenticated remote… https://f.mtr.cool/tljzmncqkb

    Post summary

    The post alerts Ivanti EPMM users that two 0‑day CVEs are actively exploited and urges immediate patching.

    000001.2K
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager_mobile---
Appivantiendpoint_manager_mobile12.5.0.0--

Explore more