CVE-2025-4428
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
- Published May 13, 2025
- CVSS 8.8 high
- 86.5% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A Metasploit module exploits it
Affected software
In the news
- APT and financial attacks on industrial organizations in Q1 2026 Kaspersky ICS CERT ·
- The Mystery OAST Host Behind a Regionally Focused Exploit Operation VulnCheck Blog ·