
🚨 In this week’s Threat Alert, we cover CVE-2025-4427, an authentication bypass in Ivanti Endpoint Manager Mobile (EPMM) that can be chained with CVE-2025-4428 for unauthenticated remote code execution. CrowdSec has observed 865 unique IP addresses sending requests matching the exploitation pattern since May 2025. Read our latest article for the full analysis, protection recommendations, and more: https://www.crowdsec.net/vulntracking-report/ivanti-epmm-cve-2025-4427-authentication-bypass Keep your network informed. Like and share this post!
Post summary
The alert details CVE‑2025‑4427 as an authentication bypass in Ivanti EPMM that can be combined with CVE‑2025‑4428 for unauthenticated RCE, and CrowdSec reports 865 unique IPs have been observed exploiting it, confirming active in‑the‑wild exploitation.


