A critical remote code execution (RCE) chain, involving CVE-2025-4427 and CVE-2025-4428, has been identified in Ivanti Endpoint Manager Mobile (EPMM) versions up to 12.5.0.0. CVE-2025-4427 allows unauthenticated attackers to bypass authentication controls via the API component, granting access to otherwise protected resources. Chaining this with CVE-2025-4428, attackers with API access can craft malicious requests to execute arbitrary code on the underlying system. The exploitation of this pre-auth RCE chain poses a severe risk of full system compromise. Ivanti has released security updates to address both flaws, and immediate patching is strongly recommended. The IONIX research team successfully validated the attack vector in a controlled environment, as detailed in this post.
References:

