Ivanti has issued security updates to address two vulnerabilities in its Endpoint Manager Mobile (EPMM) software that can be exploited for remote code execution. One of the flaws, CVE-2025-4427, has a CVSS score of 5.3 and involves an authentication bypass that allows attackers to access protected resources without the necessary credentials. These updates are crucial to safeguarding against potential attacks leveraging these vulnerabilities.
