Ivanti Addresses Critical Zero-Day Vulnerabilities in EPMM Software

Red | Vulnerability Report
Download PDF

Ivanti has patched two critical zero-day vulnerabilities, CVE-2025-4427 and CVE-2025-4428, in its on-premises Endpoint Manager Mobile (EPMM) product after they were exploited in limited attacks. These vulnerabilities allow attackers to bypass authentication and remotely execute code, potentially giving them full control over affected systems. Organizations using Ivanti EPMM are strongly urged to act quickly and apply patches immediately.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox