Ivanti EMM - Authentication Bypass (CVE-2025-4427)
Active exploitation with moderate targeting or momentum
Prioritize patching. Consider deploying a blocklist for affected CVEs.
Description
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the API.
psychologyCrowdSec Analysis
CVE-2025-4427 is an authentication bypass vulnerability affecting the API component of Ivanti Endpoint Manager Mobile, allowing unauthorized access to protected resources.
CrowdSec has been tracking this vulnerability and its exploits since 21st of May 2025.
CrowdSec network data shows that most actors exploiting CVE-2025-4427 rely on broad, untargeted scans with minimal filtering. The activity is largely automated and opportunistic in nature. Additionally, according to week-over-week analysis by CrowdSec, exploitation of CVE-2025-4427 is surging. Attack volumes are spiking well above historical norms, indicating widespread and escalating interest from threat actors. CVE-2025-4427 is currently experiencing high visibility and active exploitation across the internet.
Observed exploitation attempts are directed toward URLs containing /rs/api/v2/.
Exploitation Timeline
groupSignals collected from the CrowdSec community network.
| Event | Date |
|---|---|
| CVE Published | 2025-05-13 |
| CISA KEV | 2025-05-19 |
| Rule Released | 2025-05-21 |
| CrowdSec First Seen | 2025-05-22 |
| CISA Remediation Deadline | 2025-06-09 |
| Limited Exploitationtrending_upActive Exploitation | 2026-09-13 |
| Active Exploitationtrending_downBackground Noise | 2026-09-16 |
| Background Noisetrending_downLimited Exploitation | 2026-09-27 |
Active Attackers
Unique IPs observed exploiting this CVE in the last 14 days.
Remediation & Protection
codeAPI Access
Retrieve full intelligence data for CVE-2025-4427