References https://nvd.nist.gov/vuln/detail/CVE-2025-4427 https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM https://www.cve.org/CVERecord?id=CVE-2025-4427 https://www.ionix.io/blog/ivanti-epmm-rce-cve-2025-4427-4428/ https://www.exploit-db.com/exploits/52421 https://projectdiscovery.io/blog/ivanti-remote-code-execution https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/ https://www.wiz.io/blog/ivanti-epmm-rce-vulnerability-chain-cve-2025-4427-cve-2025-4428 https://nsfocusglobal.com/ivanti-endpoint-manager-mobile-authentication-bypass-and-remote-code-execution-vulnerability-cve-2025-4427-cve-2025-4428/ https://www.rapid7.com/blog/post/2025/05/16/etr-ivanti-epmm-exploit-chain-exploited-in-the-wild/ https://www.tenable.com/blog/cve-2025-4427-cve-2025-4428-ivanti-endpoint-manager-mobile-epmm-remote-code-execution https://github.com/watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428
Related VulnerabilitiesPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code Injection旭辰資訊|SmartIT Desktop Manager - 存在4個漏洞中成科信票务管理系统 /SystemManager/TicketSystem/ReturnTicketPlance.ashx SQL 注入漏洞中成科信票务管理系统 /SystemManager/Planetarium/ReserveTicketManagerPlane.ashx SQL 注入漏洞PoCCVE-2020-10204: Sonatype Nexus Repository Manager 3 - Remote Code ExecutionPoCccm-detect: Clear-Com Core Configuration Manager Panel - Detect智慧物联网综合服务平台ListFileManager存在目录枚举漏洞蓝凌EIS智慧协同平台 /Mobile/mobile_define.aspx/Getmobiles SQL 注入漏洞WP User Manager /profile/admin/about 文件包含漏洞(CVE-2026-9290)SteVe /steve/manager/signin 默认口令漏洞PoCCVE-2008-2052: Bitrix Site Manager 6.5 - Open RedirectPoCCVE-2025-13339: Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File ReadPoCCVE-2026-10520: Ivanti Sentry - OS Command Injection