CISA Adds Ivanti EPMM 0-day to KEV Catalog Following Active Exploitation
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical zero-day vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities (KEV) catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical zero-day vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities (KEV) catalog.
These vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, are actively exploited and pose significant risks to organizations using Ivanti’s EPMM platform.
Reported initially by CERT-EU to Ivanti, these vulnerabilities exploit a flaw in the Spring MVC's argument resolution process.
CVE-2025-4427: Exists in the API component, allowing attackers to bypass authentication by sending specially crafted API requests, due to an insecure implementation of the Spring Framework. This is associated with CWE-288 (Authentication Bypass). CVE-2025-4428: Allows authenticated attackers to execute arbitrary code remotely through crafted API requests, arising from an insecure use of the Hibernate Validator. This corresponds to CWE-94 (Code Injection).
The vulnerabilities affect the "/api/v2/featureusage" and "/api/v2/featureusage_history" endpoints.
Reported initially by CERT-EU to Ivanti, these vulnerabilities exploit a flaw in the Spring MVC's argument resolution process.
On May 15, a proof-of-concept exploit was published, increasing the risk of widespread attacks. As of May 19, 798 instances remained vulnerable, down from 940 on May 16.
CVEs Affected Products Impact Exploit Prerequisites CVSS 3.1 Score
CVE-2025-4427 Ivanti EPMM ≤12.5.0.0 (on-premises) Authentication bypass via API Network access to EPMM API endpoints 5.3 (Medium)
CVE-2025-4428 Ivanti EPMM ≤12.5.0.0 (on-premises) Authenticated RCE via code injection Network access to EPMM API endpoints, authentication (bypassed via CVE-2025-4427) 7.2 (High)
Organizations using Ivanti EPMM should upgrade to the patched versions: 11.12.0.5, 12.3.0.2, 12.4.0.2, or 12.5.0.1. Alternatively, Ivanti recommends implementing API filtering via Portal ACLs or an external WAF.
Only on-premises EPMM instances are affected; Ivanti Neurons for MDM, Ivanti Sentry, and other products remain unimpacted.
CISA’s KEV catalog has grown substantially since November 2021, with 185 vulnerabilities added in 2024, totaling 1,238 high-risk software and hardware flaws.
Based on reporting by Cyber Security News.
