logo

Multiple Vulnerabilities in Ivanti Products Could Allow for Remote Code Execution

ID: 1b7440ee-a7ee-54b7-b5e2-28227411ed91

STIX ID: report--1b7440ee-a7ee-54b7-b5e2-28227411ed91

Feed Name: CISecurity.org Advisories

Threat Score
80/100

Date Published: 2025-10-16

Date Updated: 2026-04-27

...
...

Multiple vulnerabilities have been disclosed in Ivanti products, including a critical unauthenticated path traversal in Ivanti Endpoint Manager enabling remote code execution (CVE-2025-9713), plus numerous other issues—SQL injection, OS command injection, insecure deserialization, missing auth, and MFA bypasses—across Ivanti Neurons, EPMM, and Endpoint Manager; these could allow attackers to execute code, escalate privileges, and access or modify data depending on system privileges. The report enumerates affected versions and CVEs but does not indicate active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.