Critical EPMM Patch Released by Ivanti After Exploits Detected

Critical EPMM Patch Released by Ivanti After Exploits Detected

Ivanti Acts Swiftly to Contain Targeted Exploits in EPMM Software

Ivanti has taken rapid action to mitigate emerging security threats tied to open-source components within its Endpoint Manager Mobile (EPMM) platform. The company confirmed that a limited number of on-premises EPMM environments have been exploited, triggering an immediate and coordinated incident response.

The vulnerabilities, detailed in Ivanti’s May 13, 2025 security bulletin, impact only the self-hosted version of EPMM—formerly known as MobileIron Core. Ivanti has been clear: its cloud-native solutions, such as Neurons for MDM, and other key platforms including Ivanti Sentry, are not affected.

Unlike some previous incidents, the current risks stem not from Ivanti’s own engineering but from weaknesses in embedded open-source libraries. Although no CVEs have yet been assigned, the company emphasized that it uses advanced software composition analysis tools and SBOMs (Software Bills of Materials) to continuously monitor and manage third-party code risks.

“While this issue originates outside our proprietary code, the responsibility to protect our customers remains ours,” the company stated.

Patch Now Available for On-Premises Deployments

Security patches addressing the vulnerabilities are now live. Ivanti strongly advises all organizations running on-prem EPMM to deploy the updates without delay. To ensure customers are fully supported, Ivanti has activated additional technical resources and made step-by-step remediation guidance available via its online advisory.

“Customers impacted by or concerned about these issues can access tailored assistance through our Success portal,” Ivanti confirmed. “We’ve mobilized global support teams to ensure swift resolution.”

Ongoing Investigation and Transparency Commitment

Ivanti’s security teams, in collaboration with industry partners and law enforcement, are actively investigating the scope and nature of the attacks. The company notes that no reliable atomic indicators of compromise (IoCs) are available at this stage but continues to share evolving intelligence with the security community.

This incident underscores the complex realities of software supply chain risk—even in enterprise environments. Ivanti’s approach highlights its commitment to both transparency and resilience in an era where open-source code powers critical infrastructure.

More Articles & Posts