Tech

Ivanti patches two zero-days that could lead to RCE in Endpoint Manager Mobile

Share
Share


  • Ivanti patched two flaws being chained to mount RCE attacks
  • A “limited number” of companies were allegedly compromised
  • Only on-prem products are affected

Ivanti has released a patch for two vulnerabilities in its Endpoint Manager Mobile (EPMM) software, that’s allegedly being chained in remote code execution (RCE) attacks in the wild.

The vulnerabilities are tracked as CVE-2025-4427, and CVE-2025-4428. The former is an authentication bypass in EPMM’s API, allowing threat actors to access protected resources. It was assigned a medium-severity score of 5.3.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Interlocked electrodes push silicon battery lifespan beyond limits
Tech

Interlocked electrodes push silicon battery lifespan beyond limits

Comparison of electrode-electrolyte interfacial stability between the IEE and conventional QSSE system....

Meta faces row over plan to use European data for AI
Tech

Meta faces row over plan to use European data for AI

Credit: Pixabay/CC0 Public Domain A Vienna-based privacy campaign group said Wednesday it...

White House drops Biden-era export rules aimed at curbing China’s chip access
Tech

White House drops Biden-era export rules aimed at curbing China’s chip access

US plans to drop the Biden-era diffusion rule The export restrictions were...