CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2025-4427Public Exploit

Ivanti EMM - Authentication Bypass (CVE-2025-4427)

PublishedMay 13, 2025
First SeenMay 22, 2025
Last SeenSep 29, 2026
Reported 30D784 IPs
CVSS5.3
enterprise_software
CrowdSec Score
High
6/10

Active exploitation with moderate targeting or momentum

Prioritize patching. Consider deploying a blocklist for affected CVEs.

MomentumhelpIs this threat growing, stable, or fading?
5/5
TargetedhelpTargeted attack, or spray-and-pray?
1/5

Description

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.

psychologyCrowdSec Analysis

CVE-2025-4427 is an authentication bypass vulnerability affecting the API component of Ivanti Endpoint Manager Mobile, allowing unauthorized access to protected resources.

CrowdSec has been tracking this vulnerability and its exploits since 21st of May 2025.

CrowdSec network data shows that most actors exploiting CVE-2025-4427 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature. Additionally, according to week-over-week analysis by CrowdSec, exploitation of CVE-2025-4427 is surging. Attack volumes are spiking well above historical norms, indicating widespread and escalating interest from threat actors. CVE-2025-4427 is currently experiencing high visibility and active exploitation across the internet.

Observed exploitation attempts are directed toward URLs containing /rs/api/v2/.

Exploitation Timeline

groupSignals collected from the CrowdSec community network.

EventDate
CVE Published2025-05-13
CISA KEV2025-05-19
Rule Released2025-05-21
CrowdSec First Seen2025-05-22
CISA Remediation Deadline2025-06-09
Limited Exploitationtrending_upActive Exploitation2026-09-13
Active Exploitationtrending_downBackground Noise2026-09-16
Background Noisetrending_downLimited Exploitation2026-09-27

Active Attackers

Unique IPs observed exploiting this CVE in the last 14 days.

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.

codeAPI Access

Retrieve full intelligence data for CVE-2025-4427

curl -s -H "x-api-key: YOUR_API_KEY" "https://admin.api.crowdsec.net/v1/cves/CVE-2025-4427"