Ivanti EPMM RCE Vulnerability Chain Exploited in the Wild
wiz.io | vulnerability | #rce | #exploitation | #vulnerability | #ivanti | #epmm | #cve-2025-4427 | #cve-2025-4428
Summary
Wiz details in-the-wild exploitation of Ivanti EPMM: CVE-2025-4427 (auth bypass) plus CVE-2025-4428 (Java EL injection RCE) combine into unauthenticated RCE — despite CVSS scores of 5.3 and 7.2.
- Published
- Collected
Skip to content