logo

Ivanti warns of critical Endpoint Manager code execution flaw

ID: b322b11d-c86e-50fe-ad88-26c5e2317172

STIX ID: report--b322b11d-c86e-50fe-ad88-26c5e2317172

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-12-09

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti disclosed critical and high-severity vulnerabilities in its Endpoint Manager product (notably CVE-2025-10573) that allow unauthenticated attackers to execute arbitrary JavaScript via stored XSS (requiring user interaction), potentially compromising administrator sessions; Ivanti released patches and Shadowserver reports hundreds of internet-exposed EPM instances, but there is no confirmed evidence of exploitation so far.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.