Loading
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
Use CWE-94, Ivanti vendor hub and Endpoint Manager Mobile product page to widen CVE-2025-4428 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-1340, CVE-2026-1281 and CVE-2025-4427 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 27th, 2026.