cognitive cybersecurity intelligence

News and Analysis

Search

CISA Adds Ivanti EPMM 0-day to KEV Catalog Following Active Exploitation

CISA Adds Ivanti EPMM 0-day to KEV Catalog Following Active Exploitation

CISA added two critical zero-day vulnerabilities, CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager Mobile (EPMM) to its KEV catalog. These vulnerabilities enable authentication bypass and remote code execution via API requests. Organizations should upgrade to patched versions immediately or implement API filtering to mitigate risks. The vulnerabilities underscore ongoing security concerns for Ivanti products.

Source: cybersecuritynews.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts