TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

GreyNoise

Ivanti EPMM Zero-Days: Reconnaissance to Exploitation

2025-05-16 · Read original ↗

ATT&CK techniques detected

1 predictions
T1190Exploit Public-Facing Application
67%
"ivanti epmm zero - days : reconnaissance to exploitation the bottom line : two critical ivanti zero - days ( cve - 2025 - 4427 and cve - 2025 - 4428 ) are now being actively exploited after greynoise reported a surge in scanning activity against other ivanti technologies last mon…"

Summary

Two critical Ivanti zero-days (CVE-2025-4427 and CVE-2025-4428) are now being actively exploited after a surge in scanning activity last month. When chained together, these vulnerabilities enable unauthenticated remote code execution on Ivanti Endpoint Manager Mobile systems.