Tech

Ivanti patches two zero-days that could lead to RCE in Endpoint Manager Mobile

Share
Share


  • Ivanti patched two flaws being chained to mount RCE attacks
  • A “limited number” of companies were allegedly compromised
  • Only on-prem products are affected

Ivanti has released a patch for two vulnerabilities in its Endpoint Manager Mobile (EPMM) software, that’s allegedly being chained in remote code execution (RCE) attacks in the wild.

The vulnerabilities are tracked as CVE-2025-4427, and CVE-2025-4428. The former is an authentication bypass in EPMM’s API, allowing threat actors to access protected resources. It was assigned a medium-severity score of 5.3.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
M&S cyberattacks used a little-known but dangerous technique—and anyone could be vulnerable
Tech

M&S cyberattacks used a little-known but dangerous technique—and anyone could be vulnerable

Credit: Pixabay/CC0 Public Domain The cyberattack that has targeted Marks & Spencer’s...

“We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
Tech

“We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law

Proton CEO confirmed the company will leave Switzerland if new controversial surveillance...

Ivanti Neurons for ITSM could be targeted by authentication bypass flaw, so watch out
Tech

Ivanti Neurons for ITSM could be targeted by authentication bypass flaw, so watch out

Ivanti released a patch for a critical severity flaw in Neurons for...

Researcher discusses the ‘cruel optimism’ of tech industry layoffs
Tech

Researcher discusses the ‘cruel optimism’ of tech industry layoffs

Credit: Pixabay/CC0 Public Domain In 2022, after decades of booming growth, technology...