Multiple Vulnerabilities in Ivanti Products Could Allow for Remote Code Execution
ID: 1b7440ee-a7ee-54b7-b5e2-28227411ed91
STIX ID: report--1b7440ee-a7ee-54b7-b5e2-28227411ed91
Feed Name: CISecurity.org Advisories
Multiple vulnerabilities have been disclosed in Ivanti products, including a critical unauthenticated path traversal in Ivanti Endpoint Manager enabling remote code execution (CVE-2025-9713), plus numerous other issues—SQL injection, OS command injection, insecure deserialization, missing auth, and MFA bypasses—across Ivanti Neurons, EPMM, and Endpoint Manager; these could allow attackers to execute code, escalate privileges, and access or modify data depending on system privileges. The report enumerates affected versions and CVEs but does not indicate active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
