Tech

Ivanti patches two zero-days that could lead to RCE in Endpoint Manager Mobile

Share
Share


  • Ivanti patched two flaws being chained to mount RCE attacks
  • A “limited number” of companies were allegedly compromised
  • Only on-prem products are affected

Ivanti has released a patch for two vulnerabilities in its Endpoint Manager Mobile (EPMM) software, that’s allegedly being chained in remote code execution (RCE) attacks in the wild.

The vulnerabilities are tracked as CVE-2025-4427, and CVE-2025-4428. The former is an authentication bypass in EPMM’s API, allowing threat actors to access protected resources. It was assigned a medium-severity score of 5.3.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Lenovo’s new AI Chromebook might be too smart for its own good, but it’s shockingly portable
Tech

Lenovo’s new AI Chromebook might be too smart for its own good, but it’s shockingly portable

MediaTek’s Kompanio Ultra makes a rare appearance, challenging the usual CPU suspects...

New hires are cybersecurity goldmines for hackers, and most companies don’t even realize they’re making it easy
Tech

New hires are cybersecurity goldmines for hackers, and most companies don’t even realize they’re making it easy

Most phishing incidents happen before new employees even understand how internal systems...

Analytical model evaluates performance of grant-free communication in densely populated IoT environment
Tech

Analytical model evaluates performance of grant-free communication in densely populated IoT environment

Credit: Pixabay/CC0 Public Domain Imagine a world where every smart device, from...