- The Alarming Discovery: Ivanti EPMM Vulnerabilities Being Actively Exploited
- Understanding the Twin Threats: Breaking Down the Ivanti EPMM Vulnerabilities
- Affected Systems: Is Your Organization at Risk?
- The Scope of the Threat: Limited But Significant
- Mitigation Strategies: Beyond Patching
- Additional Security Concerns: Neurons for ITSM
- The Broader Context: Ivanti’s Security Challenges
- Actionable Recommendations for Security Teams
- Conclusion: The Imperative for Rapid Response
The Alarming Discovery: Ivanti EPMM Vulnerabilities Being Actively Exploited
In a concerning development for enterprise security teams worldwide, Ivanti has released critical security updates to address two dangerous Ivanti EPMM vulnerabilities in their Endpoint Manager Mobile (EPMM) software. What makes these Ivanti EPMM vulnerabilities particularly troubling? They aren’t just theoretical risks – they’ve already been chained together by attackers to achieve remote code execution in real-world attacks.
The discovery comes at a time when organizations are increasingly dependent on mobile device management solutions to secure their remote workforces. If you’re using Ivanti’s EPMM in your environment, you’ll want to pay close attention to this situation – your security might depend on it.
Understanding the Twin Threats: Breaking Down the Ivanti EPMM Vulnerabilities
The security flaws that have security professionals scrambling to implement patches comprise two distinct but complementary Ivanti EPMM vulnerabilities:
The Gateway Vulnerability: Authentication Bypass (CVE-2025-4427)
The first vulnerability (assigned a CVSS score of 5.3) involves an authentication bypass mechanism in Ivanti’s Endpoint Manager Mobile. In plain English? This flaw allows attackers to access protected resources within your network without needing proper credentials.
Think of it as finding the key to your building’s side entrance under the doormat – once inside, intruders have bypassed your first and most critical line of defense.
The Weapon: Remote Code Execution (CVE-2025-4428)
The second vulnerability (with a more severe CVSS score of 7.2) enables remote code execution within the EPMM environment. After bypassing authentication through the first vulnerability, attackers can leverage this second flaw to run arbitrary code on targeted systems.
This is the digital equivalent of not only breaking into the building but also gaining access to the control room. From there, attackers can potentially:
- Extract sensitive data
- Move laterally through networks
- Establish persistent access
- Deploy additional malicious payloads
The Chain Reaction: How These Vulnerabilities Work Together
What makes this situation particularly dangerous is how these vulnerabilities complement each other. The authentication bypass provides the entry point, while the remote code execution vulnerability delivers the payload. Together, they create a powerful attack chain that security teams must address immediately.
Affected Systems: Is Your Organization at Risk?
The vulnerabilities impact several versions of Ivanti’s EPMM solution, specifically:
- 11.12.0.4 and prior versions (Fixed in 11.12.0.5)
- 12.3.0.1 and prior versions (Fixed in 12.3.0.2)
- 12.4.0.1 and prior versions (Fixed in 12.4.0.2)
- 12.5.0.0 and prior versions (Fixed in 12.5.0.1)
If your organization is running any of these affected versions, your systems may be vulnerable to exploitation. The good news? Patches are available now, and upgrading to the fixed versions should eliminate the security risk.
The Scope of the Threat: Limited But Significant
According to Ivanti’s disclosure, the company is “aware of a very limited number of customers who have been exploited at the time of disclosure.” This suggests that while exploitation of these Ivanti EPMM vulnerabilities isn’t widespread, threat actors are actively targeting these security flaws.
The Open-Source Connection
In an interesting twist, Ivanti revealed that the vulnerabilities are “associated with two open-source libraries integrated into EPMM.” Unfortunately, the company hasn’t disclosed which specific libraries are affected, which raises additional concerns:
- What other applications might be using these vulnerable libraries?
- Are other vendors’ products potentially vulnerable due to the same dependencies?
- How widely distributed are these vulnerable components in the software supply chain?
This lack of transparency highlights a broader issue in cybersecurity – the challenges of managing risk in software that relies heavily on open-source components.
Mitigation Strategies: Beyond Patching
While updating to the patched versions is the most comprehensive solution to remediate Ivanti EPMM vulnerabilities, Ivanti has suggested additional mitigation measures that may reduce risk:
Filtering API Access
“The risk to customers is significantly reduced if they already filter access to the API using either the built-in Portal ACLs functionality or an external web application firewall,” Ivanti noted in their security advisory.
This approach can provide an additional layer of protection by restricting which systems can communicate with vulnerable components.
Cloud Users Are Safe
If you’re using Ivanti’s cloud-based solutions rather than on-premises deployments, there’s good news – the cloud version isn’t affected. Specifically, Ivanti confirmed that the vulnerability “only affects the on-prem EPMM product. It is not present in Ivanti Neurons for MDM, Ivanti’s cloud-based unified endpoint management solution, Ivanti Sentry, or any other Ivanti products.”
This highlights one of the security advantages of cloud-based solutions – vendors can often patch vulnerabilities more quickly and consistently across their customer base.
Additional Security Concerns: Neurons for ITSM
In what appears to be a busy period for Ivanti’s security team, the company has also addressed a separate high-severity vulnerability:
- CVE-2025-22462 (CVSS score: 9.8) – An authentication bypass flaw in on-premise versions of Neurons for ITSM that could allow remote unauthenticated attackers to gain administrative access.
With a CVSS score of 9.8, this vulnerability is classified as critical and requires immediate attention from affected organizations. The good news is that, as of the disclosure, there’s no evidence that this particular vulnerability has been exploited in the wild.
The Broader Context: Ivanti’s Security Challenges
This isn’t the first time Ivanti products have been targeted by threat actors. In recent years, zero-day Ivanti EPMM vulnerabilities and flaws in other Ivanti appliances have become what security experts describe as a “lightning rod for threat actors.”
Why Are Ivanti Products Attractive Targets?
Several factors make Ivanti products particularly attractive to attackers:
- Widespread enterprise adoption: Ivanti solutions are deployed across numerous large organizations worldwide
- Privileged access: These tools often have extensive access rights within corporate networks
- Gateway position: Many Ivanti products serve as entry points to internal networks
- Critical functionality: Organizations depend on these tools for daily operations, making them less likely to be taken offline during patching
Actionable Recommendations for Security Teams
If your organization uses Ivanti EPMM or other Ivanti products, here are the steps you should take immediately to protect against these Ivanti EPMM vulnerabilities:
- Identify vulnerable systems: Conduct an inventory to locate all installations of Ivanti EPMM and determine which versions are running
- Apply patches ASAP: Update to the fixed versions as quickly as possible
- Update to 11.12.0.5 (if running 11.12.0.4 or prior)
- Update to 12.3.0.2 (if running 12.3.0.1 or prior)
- Update to 12.4.0.2 (if running 12.4.0.1 or prior)
- Update to 12.5.0.1 (if running 12.5.0.0 or prior)
- Implement mitigations: If immediate patching isn’t possible, filter API access using Portal ACLs or a web application firewall
- Monitor for compromise: Given the active exploitation, conduct a thorough investigation to determine if your systems have already been compromised
- Consider cloud migration: Evaluate whether moving to Ivanti’s cloud-based solutions might reduce future security risks
Conclusion: The Imperative for Rapid Response
The discovery of these actively exploited Ivanti EPMM vulnerabilities serves as yet another reminder of the importance of rapid security patching. While the number of exploitations appears limited at this time, history suggests that once Ivanti EPMM vulnerabilities are publicly disclosed, the window for exploitation widens dramatically.
Security teams should prioritize these patches and implement them as quickly as possible. Additionally, this incident highlights the continuing challenge of supply chain security, particularly when it comes to open-source components embedded within commercial software.
As always in cybersecurity, vigilance and speed are your strongest allies. Don’t wait – patch now.
Frequently asked questions.
Answers connected directly to this article and its subject.
01 What exactly are the Ivanti EPMM vulnerabilities that were discovered?
Two critical Ivanti EPMM vulnerabilities were found: CVE-2025-4427, an authentication bypass flaw (CVSS 5.3), and CVE-2025-4428, a remote code execution vulnerability (CVSS 7.2). When chained together, these Ivanti EPMM vulnerabilities allow attackers to access protected resources without authentication and then execute malicious code on the target system.
02 How do I know if my organization is affected by Ivanti EPMM Vulnerabilities?
Your organization is potentially vulnerable to these Ivanti EPMM vulnerabilities if you’re running on-premises Ivanti EPMM versions 11.12.0.4 or prior, 12.3.0.1 or prior, 12.4.0.1 or prior, or 12.5.0.0 or prior. Cloud-based Ivanti solutions like Ivanti Neurons for MDM are not affected by these particular Ivanti EPMM vulnerabilities.
03 Have these vulnerabilities been exploited in the wild?
Yes, according to Ivanti, a “very limited number of customers” have already been targeted with attacks exploiting these vulnerabilities. This makes patching even more urgent, as threat actors are actively using these flaws.
04 What should I do if I can't patch immediately?
If immediate patching isn’t possible, Ivanti recommends filtering access to the API using either the built-in Portal ACLs functionality or an external web application firewall. This can significantly reduce your risk of exploitation while you prepare to deploy the patches.
05 Are other Ivanti products affected by similar vulnerabilities?
Ivanti has also disclosed a separate critical vulnerability (CVE-2025-22462, CVSS 9.8) in on-premise versions of Neurons for ITSM. This flaw could allow unauthenticated attackers to gain administrative access. However, there’s currently no evidence of exploitation for this particular vulnerability.
