CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Critical Ivanti Endpoint Manager XSS Flaw Disclosed

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Ivanti has disclosed a critical stored cross-site scripting (XSS) vulnerability (CVE-2025-10573) in its Endpoint Manager (EPM) solution, allowing unauthenticated remote code execution with user interaction. The flaw affects versions prior to 2024 SU4 SR1 and is mitigated by the solution's typical offline deployment. Ivanti also patched three high-severity vulnerabilities (CVE-2025-13659, CVE-2025-13662) enabling arbitrary code execution under specific conditions. No exploitation has been observed, but Ivanti EPM flaws have been targeted before, including CISA-alerted vulnerabilities in March 2024.

Timeline

  1. 09.12.2025 19:10 1 articles · 10h ago

    Ivanti Endpoint Manager XSS Flaw Disclosed and Patched

    Ivanti disclosed a critical XSS flaw (CVE-2025-10573) in Endpoint Manager, enabling unauthenticated remote code execution with user interaction. The flaw affects versions prior to 2024 SU4 SR1 and is mitigated by typical offline deployment. Ivanti also patched three high-severity vulnerabilities (CVE-2025-13659, CVE-2025-13662) requiring user interaction for exploitation. No exploitation has been observed, but Ivanti EPM has been targeted before, including CISA-alerted flaws in March 2024.

    Show sources

Information Snippets