Two critical security vulnerabilities have been discovered in Ivanti Endpoint Manager Mobile (EPMM), with evidence of active exploitation in the wild. The vulnerability chain consists of CVE-2025-4427, an authentication bypass flaw with a CVSS score of 5.3, and CVE-2025-4428, a remote code execution vulnerability with a CVSS score of 7.2. The discovery emerges amid growing concerns about authentication bypass techniques in enterprise security systems.
The combined vulnerabilities allow attackers to execute arbitrary code on affected systems without proper authentication. The security issues originate from two open-source libraries integrated into EPMM, including “hibernate-validator” and another unspecified library. The incident highlights the ongoing challenges in mobile identity management security, particularly in enterprise environments where mobile device management platforms are crucial for organizational security.
The affected versions of Ivanti EPMM include 11.12.0.4 and prior, 12.3.0.1 and prior, 12.4.0.1 and prior, and 12.5.0.0 and prior. Ivanti has released patches addressing these vulnerabilities in versions 11.12.0.5, 12.3.0.2, 12.4.0.2, and 12.5.0.1 respectively. The rapid response from Ivanti demonstrates lessons learned from previous security incidents, including the company’s research on increasing cybersecurity threats targeting IT departments.
CERT-EU initially reported the vulnerabilities to Ivanti. The company has confirmed that “a very limited number of customers,” were exploited at the time of disclosure. To mitigate risk, Ivanti recommends customers apply the latest security updates available through their download portal. Additional protective measures include implementing Portal ACLs or external Web Application Firewall (WAF) filtering to restrict API access.
Security researchers have developed a proof-of-concept tool demonstrating the vulnerability chain’s exploitation, which has been published on GitHub. Detection mechanisms are available through Sigma rules on platforms such as SOC Prime. The development is particularly concerning given the recent surge in mobile authentication exploitation across various sectors.
Sources: The Hacker News, SOC Prime, Wiz, Watchtowr Labs, Cyber Daily