CVE-2025-4428: Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-05-19. EPSS: 87% chance of exploitation in the next 30 days.

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

Affected products

  • Ivanti Endpoint Manager Mobile: before 11.12.0.5 (fixed in 11.12.0.5); from 12.3.0.0, before 12.3.0.2 (fixed in 12.3.0.2); from 12.4.0.0, before 12.4.0.2 (fixed in 12.4.0.2); version 12.5.0.0 only

Published 2025-05-13. Last modified 2026-06-17.