PatchSiren cyber security CVE debrief
CVE-2025-4428 Ivanti CVE debrief
CVE-2025-4428 is a code injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM). CISA added it to the Known Exploited Vulnerabilities catalog on 2025-05-19 and set a remediation due date of 2025-06-09, so organizations using EPMM should treat it as a high-priority exposure and apply vendor mitigations or discontinue use if mitigations are unavailable.
- Vendor
- Ivanti
- Product
- Endpoint Manager Mobile (EPMM)
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2025-05-19
- Original CVE updated
- 2025-05-19
- Advisory published
- 2025-05-19
- Advisory updated
- 2025-05-19
Who should care
Ivanti EPMM administrators, MDM/MEM platform owners, security operations, vulnerability management, and incident response teams responsible for EPMM deployments.
Technical summary
The supplied sources identify CVE-2025-4428 as a code injection vulnerability affecting Ivanti Endpoint Manager Mobile (EPMM). CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2025-05-19, with a remediation due date of 2025-06-09 and guidance to apply vendor mitigations or discontinue use if mitigations are unavailable. The corpus does not include affected versions, exploit mechanics, or a CVSS score.
Defensive priority
Critical
Recommended defensive actions
- Inventory all Ivanti Endpoint Manager Mobile (EPMM) deployments and confirm whether any instance is exposed or mission-critical.
- Apply vendor mitigations or patches according to Ivanti guidance as soon as possible.
- Prioritize remediation before the CISA KEV due date of 2025-06-09.
- If mitigations are unavailable, follow CISA guidance to discontinue use of the product.
- Review EPMM-related logs, alerts, and administrative activity for suspicious or unexpected behavior.
- Validate incident-response and recovery plans in case containment is needed.
Evidence notes
The source corpus is limited to CISA's Known Exploited Vulnerabilities feed plus official CVE/NVD references. The KEV entry explicitly marks CVE-2025-4428 as known exploited, lists the product as Ivanti Endpoint Manager Mobile (EPMM), sets dateAdded to 2025-05-19 and dueDate to 2025-06-09, and records knownRansomwareCampaignUse as Unknown. No CVSS score or affected-version data was supplied in the corpus.
Official resources
-
CVE-2025-4428 CVE record
CVE.org
-
CVE-2025-4428 NVD detail
NVD
-
CISA Known Exploited Vulnerabilities catalog
CISA - Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
-
Source item URL
cisa_kev
CISA classified CVE-2025-4428 as a Known Exploited Vulnerability on 2025-05-19. The corpus does not provide additional disclosure details beyond that designation and the remediation guidance in the KEV metadata.