logo

Multiple Vulnerabilities in Ivanti Products Could Allow for Remote Code Execution

ID: cf0d0d98-0d53-518e-86aa-8efa87ae4971

STIX ID: report--cf0d0d98-0d53-518e-86aa-8efa87ae4971

Feed Name: CISecurity.org Advisories

Threat Score
75/100

Date Published: 2025-09-09

Date Updated: 2026-04-27

...
...

Multiple critical and lower-severity vulnerabilities were disclosed in Ivanti products. The most severe allows remote unauthenticated remote code execution against Ivanti Endpoint Manager (CVE-2025-9712, CVE-2025-9872); additional flaws include missing authorization, CSRF, SSRF, reflected text injection and denial-of-service across Ivanti Connect Secure, Policy Secure, ZTA Gateway and Neurons for Secure Access in specified pre-patch versions (fixes noted as deployed 02-Aug-2025). Successful exploitation could permit attackers to execute code, install programs, and view, change, or delete data depending on system privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.