More

    Ivanti patches two zero-days that could lead to RCE in Endpoint Manager Mobile




    • Ivanti patched two flaws being chained to mount RCE attacks
    • A “limited number” of companies were allegedly compromised
    • Only on-prem products are affected

    Ivanti has released a patch for two vulnerabilities in its Endpoint Manager Mobile (EPMM) software, that’s allegedly being chained in remote code execution (RCE) attacks in the wild.

    The vulnerabilities are tracked as CVE-2025-4427, and CVE-2025-4428. The former is an authentication bypass in EPMM’s API, allowing threat actors to access protected resources. It was assigned a medium-severity score of 5.3.

    https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img