Ivanti patches two days zero that could lead to RCE in Endpoint Mobile Manager


  • Ivanti has corrected two chained faults to set up RCE attacks
  • A “limited number” of companies would have been compromised
  • Only on -site products are affected

Ivanti has published a corrective for two vulnerabilities in its mobile manager Endpoint Manager (EPMM), which would have been chained in remote code execution attacks (RCE) in nature.

Vulnerabilities are followed under the name of CVE-2025-4427 and CVE-2025-4428. The first is an authentication bypass in the EPMM API, allowing threat actors to access protected resources. It was attributed to an average score of 5.3.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top