• News/
  • https://www.theregister.com/2025/05/14/ivanti_patches_two_zerodays_and/

Ivanti patches two zero-days under active attack as intel agency warns customers

The Register
·
Connor Jones
·
Published May 14, 2025
·
Updated

Australia's intelligence agency is warning organizations about several new Ivanti zero-days chained for remote code execution (RCE) attacks. The vendor itself has said the vulns are linked to two mystery open source libraries which it declined to name. The Australian Signals Directorate (ASD) issued a critical warning about CVE-2025-4427 (5.3) and CVE-2025-4428 (7.2) earlier today. Individually, the two bugs seem fairly unalarming, but together they can be, and have been, used to exploit Ivanti customers. We are actively working with our security partners and the maintainers of the libraries to determine if a CVE against the libraries is warranted for the benefit of the broader security ecosystem "We are aware of a very limited number of customers whose solution has been exploited at the time of disclosure," said Ivanti in its advisory, which was released alongside the patches for Ivanti Endpoint Manager Mobile (EPMM). EPMM is used by Ivanti customers to manage company-issued devices and applications on those devices, while providing secure access to sensitive or confidential content such as company documents. Although EPMM can be used by all types of organizations, the ASD's advisory stated that the information was intended for large organizations and government entities, suggesting the EPMM vulnerabilities are less likely to affect smaller companies. The affected EPMM versions include: All four series of the software have patches available, but if customers can't apply them...

Read full article

Affected Software

6 affected components
Ivanti Endpoint Manager Mobile
Ivanti Neurons for ITSM=2023.4
Ivanti Neurons for ITSM=2024.2
Ivanti Neurons for ITSM=2024.3
Ivanti Endpoint Manager Mobile=5.3
Ivanti Endpoint Manager Mobile=7.2
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses security patches released by Ivanti for two zero-day vulnerabilities currently under active exploitation.

2

What security implications are discussed in relation to the vulnerabilities?

The vulnerabilities are linked to remote code execution (RCE) attacks, posing a significant threat to affected systems.

3

Which Ivanti products are affected by these zero-day vulnerabilities?

The vulnerabilities impact Ivanti Endpoint Manager Mobile and Ivanti Neurons for ITSM versions 2023.4, 2024.2, and 2024.3.

4

What action has Ivanti taken concerning these vulnerabilities?

Ivanti has released patches to mitigate the risks associated with the identified zero-day vulnerabilities.

5

Which organization has issued a warning related to these Ivanti vulnerabilities?

Australia's intelligence agency has warned organizations about the active exploitation of the Ivanti zero-days.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203