Critical Security Gaps in Ivanti EPMM: Nearly 800 Systems Still Exposed
Two previously unknown vulnerabilities have been uncovered in Ivanti’s Endpoint Manager Mobile (EPMM), forming a dangerous exploit chain that grants threat actors unauthenticated remote code execution capabilities.
Unlike typical zero-day disclosures, these flaws—tracked as CVE-2025-4427 and CVE-2025-4428—have already been weaponized in active attacks. Security intelligence from the Shadowserver Foundation confirms that hundreds of EPMM instances remain internet-facing and exploitable as of the latest scans.
The discovery was originally reported to Ivanti by CERT-EU and formally disclosed on May 13, 2025. In response, Ivanti acknowledged a “very limited number” of affected customers had already experienced compromise before mitigations could be implemented.
What Makes This Chain Dangerous?
- CVE-2025-4427 enables attackers to bypass authentication controls entirely, exploiting a flaw with a CVSS base score of 5.3.
- When combined with CVE-2025-4428, attackers can escalate their access to execute arbitrary code on target systems—without credentials or user interaction.
Limited Scope, High Risk
Ivanti has clarified that only self-managed, on-premises deployments of EPMM are susceptible. Customers using its cloud-native platforms, including Ivanti Neurons for MDM, are insulated from these particular threats.
This incident underscores a growing trend: on-premises infrastructure remains a favored target for adversaries, particularly when patch management and segmentation are lacking.
Security teams are urged to audit their EPMM deployments immediately, prioritize patch application, and isolate any vulnerable endpoints from the internet until fixes are fully applied.

Inside CVE-2025-4428: Authenticated RCE via Exploited API Logic
CVE-2025-4428 is a high-impact vulnerability that enables remote code execution (RCE) through misused API behavior, carrying a CVSS severity score of 7.2. Unlike unauthenticated threats, this flaw requires the attacker to already have access—but once inside, the path to exploitation is swift and direct.
Exploitation Vector
The weakness lies in the handling of requests to the /mifs/rs/api/v2/featureusage endpoint. Attackers can inject specially crafted HTTP GET requests, abusing the format parameter to deliver malicious payloads that trigger code execution.
This vulnerability isn’t rooted in surface-level API design flaws, but in deeper backend mechanics—specifically, unsafe use of Expression Language (EL) processing within the hibernate-validator library. This misconfiguration allows arbitrary expression evaluation where none should be possible, effectively turning API input into an execution engine.
Key Takeaway
While access is gated by authentication, this bug dramatically lowers the barrier to escalation once attackers are inside the perimeter. It’s a sharp reminder that internal API surfaces can become high-risk assets when underlying components are not securely configured.

Payload Execution Confirmed: Output Echoed in Server Error Responses
Once activated, the malicious payload leverages the vulnerable code path to execute system-level commands. The resulting output doesn’t go unnoticed—it’s surfaced directly within server error responses, offering attackers immediate feedback and confirmation of success.
Live Exposure Snapshot
Real-world impact has already been measured. According to telemetry from the Shadowserver Foundation, 940 exposed systems were flagged as vulnerable on May 15. By May 18, that number dipped slightly to 798—highlighting slow remediation despite active exploitation.
These figures underscore an urgent gap: although awareness is growing, hundreds of instances remain exploitable in the wild, sustaining a critical attack surface for adversaries.

Global Hotspots and Escalating Threat: Ivanti EPMM Exploits Surge as PoC Code Circulates
The global map of risk is rapidly shifting. Germany currently leads with 276 vulnerable Ivanti EPMM systems still exposed, followed by the United States with 150, according to infrastructure-wide scanning by the Shadowserver Foundation.
In a post on May 19, Shadowserver confirmed ongoing probes targeting Ivanti deployments susceptible to the CVE-2025-4427 vulnerability—particularly in scenarios where it’s paired with CVE-2025-4428 for full remote code execution. “We’re scanning for unpatched instances,” the organization reported, signaling continuous threat intelligence monitoring.
Patch Now: Versions at Risk
Multiple branches of Ivanti EPMM are affected, with at-risk versions including:
- 11.12.0.4 and earlier
- 12.3.0.1 and earlier
- 12.4.0.1 and earlier
- 12.5.0.0
Ivanti has since issued critical fixes in the form of versions 11.12.0.5, 12.3.0.2, 12.4.0.2, and 12.5.0.1. Still, the update curve is lagging behind the attacker curve—and the threat window is wide open.
From Targeted to Mass Exploitation
Security officials are raising red flags. The UK’s NHS England National Cyber Security Operations Centre warns that further attacks are “highly likely,” particularly with working proof-of-concept (PoC) exploit code now circulating publicly.
Researchers at watchTowr issued a blunt reminder: once stealthy campaigns are exposed, threat actors tend to pivot hard. “When targeted operations go public, opportunistic attackers flood the field and exploit anything left unprotected,” they said.
Urgent Actions for EPMM Users
Organizations still running on-premises Ivanti EPMM environments must:
- Apply the latest patches immediately
- Conduct thorough compromise assessments
- Review logs in response to any alerts from monitoring systems
This isn’t an isolated case. It’s the latest in a troubling pattern of zero-day vulnerabilities impacting Ivanti’s product ecosystem—including VPNs, ICS, IPS, and ZTA gateways—that have been repeatedly leveraged by attackers.




