Ivanti warns of critical Endpoint Manager code execution flaw
ID: b322b11d-c86e-50fe-ad88-26c5e2317172
STIX ID: report--b322b11d-c86e-50fe-ad88-26c5e2317172
Feed Name: Bleeping Computer
Threat Score
Ivanti disclosed critical and high-severity vulnerabilities in its Endpoint Manager product (notably CVE-2025-10573) that allow unauthenticated attackers to execute arbitrary JavaScript via stored XSS (requiring user interaction), potentially compromising administrator sessions; Ivanti released patches and Shadowserver reports hundreds of internet-exposed EPM instances, but there is no confirmed evidence of exploitation so far.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
