Ivanti Patches two zero days that can lead to RCE in the Endpoint Manager Mobile


  • Ivanti patched two deficiencies that were tied to Mount RCE -attack
  • A “limited number” of businesses were allegedly compromised
  • Only on-prem products are affected

Ivanti has released a patch to two vulnerabilities in its Endpoint Manager Mobile (EPMM) software that has allegedly been linked to Remote Code Execution (RCE) attacks in nature.

The vulnerabilities are traced as CVE-2025-4427 and CVE-2025-4428. The former is an approval compass in EPMMS API, giving threat players access to protected resources. It was awarded to a medium-difficult score of 5.3.

Leave a Comment

Your email address will not be published. Required fields are marked *