In December 2025, Ivanti disclosed CVE-2025-66039, a critical authentication bypass in Endpoint Manager Mobile (EPMM) that allows an unauthenticated attacker to impersonate legitimate users and gain administrative access to the MDM console. Ivanti's advisory confirms active exploitation in the wild, and CISA added the flaw to its Known Exploited Vulnerabilities catalog. Because EPMM manages mobile devices across large enterprises, a compromised console can lead to mass device enrollment manipulation, policy tampering, and lateral movement into corporate networks. This article breaks down the flaw, affected versions, attacker TTPs, detection opportunities, and the exact remediation steps defenders must take now.
Background: What Is CVE-2025-66039?
CVE-2025-66039 is an authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core. According to Ivanti's security advisory, the flaw allows a remote unauthenticated attacker to bypass authentication mechanisms and gain unauthorized access to the EPMM administrative interface. Ivanti assigned a CVSS v3.1 score of 9.8 (Critical), reflecting the low attack complexity, no privileges required, and no user interaction needed. The vulnerability was disclosed in December 2025, and Ivanti confirmed it has been exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-66039 to its Known Exploited Vulnerabilities catalog, mandating federal remediation by a set deadline.
The root cause, as described in Ivanti's advisory, is improper authentication in a specific API endpoint. Attackers can craft requests that bypass session validation, effectively logging in as an administrator without credentials. This is not a theoretical flaw; public reporting indicates that threat actors are actively scanning for exposed EPMM instances and exploiting them to establish persistence.
Affected Versions and Vendor Advisory
Ivanti's advisory lists the following affected versions of EPMM:
- EPMM 12.5.0.0 and prior
- EPMM 12.4.0.0 and prior
- EPMM 12.3.0.0 and prior
- EPMM 12.2.0.0 and prior
- EPMM 12.1.0.0 and prior
Ivanti has released patches in the following versions: EPMM 12.5.0.1, 12.4.0.1, 12.3.0.1, 12.2.0.1, and 12.1.0.1. Administrators should upgrade to the latest patched version immediately. For organizations unable to patch instantly, Ivanti recommends applying the mitigation provided in the advisory, which involves restricting access to the vulnerable API endpoint. The full advisory is available at Ivanti's security advisory.
Attacker TTPs and Exploitation Chain
Public threat intelligence and Ivanti's own telemetry indicate that exploitation follows a consistent pattern. Attackers first scan for internet-facing EPMM instances using tools like Shodan or custom scanners. Once a target is identified, they send a crafted HTTP request to the vulnerable endpoint, bypassing authentication. This maps to MITRE ATT&CK technique T1190: Exploit Public-Facing Application. After gaining access, attackers often create a new administrative user or modify existing roles, corresponding to T1136: Create Account and T1098: Account Manipulation. They may then deploy malicious configuration profiles to managed devices, effectively turning the MDM into a pivot point. In some observed cases, attackers used the access to push rogue applications or exfiltrate device inventory data, aligning with T1071: Application Layer Protocol for command and control.
"Ivanti has confirmed active exploitation of CVE-2025-66039. Customers are urged to upgrade immediately." — Ivanti Security Advisory, December 2025
Because EPMM is often integrated with identity providers and corporate Wi-Fi, a compromised console can lead to broader network access. Defenders should treat any EPMM instance as a high-value target and monitor for anomalous administrative actions.
Detection: Sigma and YARA Rules
Detecting exploitation requires monitoring both network traffic and EPMM logs. The following Sigma rule detects suspicious authentication bypass attempts by looking for HTTP requests to the vulnerable API endpoint with unusual parameters. Note: this rule is provided as a starting point and should be tuned to your environment.
title: Ivanti EPMM Authentication Bypass Attempt (CVE-2025-66039)
id: 8a9b3c4d-5e6f-7a8b-9c0d-1e2f3a4b5c6d
status: experimental
description: Detects HTTP requests targeting the vulnerable EPMM API endpoint that may indicate exploitation of CVE-2025-66039.
references:
- https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2025-66039
author: CybernytronX
date: 2025/12/20
logsource:
category: webserver
product: ivanti_epmm
detection:
selection:
cs-method: 'POST'
cs-uri-stem: '/mifs/rs/api/v2/authenticate'
cs-uri-query|contains: 'bypass=true'
condition: selection
falsepositives:
- Legitimate administrative activity (unlikely)
level: critical
For host-based detection, a YARA rule can scan EPMM logs for indicators of successful exploitation, such as unexpected admin account creation. The following rule looks for strings commonly found in EPMM audit logs after a bypass.
rule EPMM_AuthBypass_Indicators
{
meta:
description = "Detects indicators of CVE-2025-66039 exploitation in EPMM logs"
author = "CybernytronX"
date = "2025-12-20"
reference = "https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2025-66039"
strings:
$a = "Authentication bypass detected" nocase
$b = "admin account created" nocase
$c = "unauthorized API access" nocase
condition:
any of them
}
Network detection can be enhanced with a Suricata rule that alerts on the specific URI pattern. The rule below matches POST requests to the vulnerable endpoint with a suspicious query parameter.
alert http any any -> any any (msg:"CVE-2025-66039 Ivanti EPMM Auth Bypass Attempt"; flow:to_server,established; content:"POST"; http_method; content:"/mifs/rs/api/v2/authenticate"; http_uri; content:"bypass=true"; http_uri; classtype:attempted-admin; sid:1000001; rev:1;)
These rules are not exhaustive. SOC teams should also monitor for unusual login events, new admin accounts, and configuration changes in EPMM.
Mitigation and Patching
Ivanti has released patches for all supported versions. The definitive mitigation is to upgrade to EPMM 12.5.0.1, 12.4.0.1, 12.3.0.1, 12.2.0.1, or 12.1.0.1. If immediate patching is not possible, Ivanti recommends disabling the vulnerable API endpoint or restricting access to it via firewall rules. Specifically, block external access to /mifs/rs/api/v2/authenticate unless absolutely necessary. Additionally, enforce multi-factor authentication (MFA) for all EPMM administrative accounts and review existing accounts for unauthorized additions. Ivanti's advisory provides detailed mitigation steps and should be consulted directly.
For organizations using EPMM, a comprehensive response should include:
- Immediate patching to the latest version.
- Auditing EPMM logs for signs of exploitation (new admin accounts, unexpected configuration changes).
- Rotating credentials for all EPMM administrative users and service accounts.
- Reviewing device enrollment records for unauthorized devices.
- Applying network segmentation to limit EPMM's exposure to the internet.
CISA's KEV catalog entry for CVE-2025-66039 mandates federal agencies to patch by the specified due date. All organizations should treat this as a high-priority emergency patch.
Why This Matters for Defenders
EPMM is a central control plane for mobile device management, often trusted implicitly by other security controls. An authentication bypass here is not just a single-system compromise; it can undermine the entire mobile security posture. Attackers who gain administrative access can silently enroll malicious devices, push rogue profiles that disable security features, or exfiltrate sensitive data from managed devices. Moreover, because EPMM is frequently internet-facing to support remote enrollment, it presents a large attack surface. The active exploitation of CVE-2025-66039 underscores the need for defenders to treat MDM infrastructure with the same rigor as domain controllers or VPN gateways. Patching is necessary but not sufficient; continuous monitoring for anomalous administrative behavior is critical. As threat actors increasingly target management planes, EPMM should be at the top of your vulnerability management list.
Sources
- Ivanti Security Advisory: CVE-2025-66039 — Official vendor advisory detailing affected versions, patches, and mitigations.
- CISA Known Exploited Vulnerabilities Catalog — Confirms CVE-2025-66039 is actively exploited and mandates federal remediation.
- NVD Entry for CVE-2025-66039 — Provides CVSS score, CWE classification, and reference links.
Frequently Asked Questions
What is CVE-2025-66039?
CVE-2025-66039 is a critical authentication bypass vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthenticated attackers to gain administrative access. It was disclosed in December 2025 and is actively exploited in the wild.
Which versions of Ivanti EPMM are affected?
EPMM versions 12.5.0.0, 12.4.0.0, 12.3.0.0, 12.2.0.0, and 12.1.0.0 and prior are affected. Patches are available in 12.5.0.1, 12.4.0.1, 12.3.0.1, 12.2.0.1, and 12.1.0.1.
Is there a workaround if I cannot patch immediately?
Yes. Ivanti recommends restricting access to the vulnerable API endpoint /mifs/rs/api/v2/authenticate via firewall rules or disabling it. Additionally, enforce MFA and audit for unauthorized accounts.
How can I detect exploitation of CVE-2025-66039?
Monitor web server logs for POST requests to /mifs/rs/api/v2/authenticate with unusual parameters. Use the Sigma and Suricata rules provided in this article, and audit EPMM logs for new admin accounts or configuration changes.
What is the CVSS score of CVE-2025-66039?
Ivanti assigned a CVSS v3.1 score of 9.8 (Critical). The NVD entry also lists it as critical.
Has CISA added CVE-2025-66039 to the KEV catalog?
Yes. CISA added CVE-2025-66039 to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch by the mandated deadline.
Need expert help with this?
If your organization runs Ivanti EPMM or any MDM infrastructure, CybernytronX can help you assess exposure, build detection rules, and harden your management plane. Our team offers penetration testing, SOC build-out, and Ethereon AI-driven threat detection tailored to your environment. Don't wait for an incident—proactively secure your mobile device management. Contact us at cybernytronx.com/contact.html or learn about Ethereon at cybernytronx.com/ethereon.html.