Ivanti patched two deficiencies that were tied to Mount RCE -attack
A “limited number” of businesses were allegedly compromised
Only on-prem products are affected
Ivanti has released a patch to two vulnerabilities in its Endpoint Manager Mobile (EPMM) software that has allegedly been linked to Remote Code Execution (RCE) attacks in nature.
The vulnerabilities are traced as CVE-2025-4427 and CVE-2025-4428. The former is an approval compass in EPMMS API, giving threat players access to protected resources. It was awarded to a medium-difficult score of 5.3.