CVE-2025-4427
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
9 articles
EPSS Score
Source: FIRST.org · 2026-05-24
91.32%
probability
This CVE has a 91.32% probability
of being exploited in the next 30 days.
0%
Top 99.7th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Exploits & PoC
watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428
PoC CVE-2025-4427 — watchtowrlabs/watchTowr-vs-Ivanti-EPMM-CVE-2025-4427-CVE-2025-4428
11
1 repo — triés par ⭐
Rechercher sur GitHub ↗
Hackers Exploit SharePoint Zero-Day Since July 7 to Steal Keys, Maintain Persistent Access
TheHackerNews
Ivanti fixes EPMM zero-days chained in code execution attacks
BleepingComputer
May 13, 2025
Ivanti Patches EPMM Vulnerabilities Exploited for Remote Code Execution in Limited Attacks
TheHackerNews
CISA exposes malware kits deployed in Ivanti EPMM attacks
BleepingComputer
Sep 19, 2025
CISA Warns of Two Malware Strains Exploiting Ivanti EPMM CVE-2025-4427 and CVE-2025-4428
TheHackerNews
New ForumTroll Phishing Attacks Target Russian Scholars Using Fake eLibrary Emails
TheHackerNews
Dec 17, 2025
Security Advisory 2025-018
CERT-EU
May 16, 2025
Multiples vulnérabilités dans Ivanti Endpoint Manager Mobile (EPMM) (14 mai 2025)
CERT-FR
May 14, 2025
Signal Intelligence
Confidence
85%
EPSS
91.32%
Mentions
9
Last Seen
Dec 17, 2025
CNA Information
Analyst Note
CVE-2025-4427 is explicitly named as a zero-day in the BleepingComputer article title 'Ivanti fixes EPMM zero-days chained in code execution attacks' with active exploitation confirmed by CISA exposure of malware kits. Published May 2025 with immediate exploitation evidence supports zero-day classification.
Threat Actors 31
Lazarus Group
apt_group
Information theft and espionage
🇰🇵 KP
APT27
apt_group
Information theft and espionage
🇨🇳 CN
Cobalt
apt_group
Financial crime
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
SCATTERED SPIDER
apt_group
Financial crime
🇺🇸 US
The Shadow Brokers
apt_group
🇷🇺 RU
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
APT-C-36
apt_group
Information theft and espionage
🇨🇴 CO
Comment Crew
apt_group
Information theft and espionage
🇨🇳 CN
FASTCash
apt_group
Information theft and espionage
🇰🇵 KP
[Unnamed group]
apt_group
🇨🇳 CN
RomCom
apt_group
Financial gain
🇷🇺 RU
Silent Lynx
apt_group
Information theft and espionage
🇰🇿 KZ
TraderTraitor
apt_group
🇰🇵 KP
UTA0178
apt_group
Information theft and espionage
🇨🇳 CN
Returned Libra
apt_group
🇨🇳 CN
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
SOLAR SPIDER
apt_group
🇨🇳 CN
Bitwise Spider
apt_group
Financial gain
🇷🇺 RU
LapDogs
apt_group
🇨🇳 CN
Pat Bear
apt_group
🇸🇾 SY
Unnamed Actor
apt_group
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
SINGING SPIDER
apt_group
🇺🇸 US
Mana Team
apt_group
🇨🇳 CN
MIMIC SPIDER
apt_group
🇺🇸 US
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Cyber Alliance
apt_group
🇺🇦 UA
Beijing Group
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 05, 2026