Ivanti Endpoint Manager stored XSS (CVE-2025-10573)
Vulnerability
Summary
Hide ▲
Show ▼
Ivanti disclosed CVE-2025-10573, a critical stored XSS in Endpoint Manager (EPM) prior to 2024 SU4 SR1 that can let a remote unauthenticated attacker execute JavaScript in an administrator session and potentially reach remote code execution. The issue matters most for internet-facing EPM instances, and Shadowserver says there are still hundreds of them exposed. Ivanti has released a fix, so affected customers should patch immediately.
Related Happenings
CISA emergency patch deadline for Ivanti EPMM
Public Sector Action
H score40
First: 08.05.2026 15:16
Last: 08.05.2026 15:16
Sources 1
About this happening:
CISA ordered U.S. federal agencies to patch Ivanti EPMM by midnight Sunday, May 10 after adding CVE-2026-6973 to its list of vulnerabilities exploited in attacks....
CISA emergency patch deadline for Ivanti EPMM
Public Sector ActionAbout this happening: CISA ordered U.S. federal agencies to patch Ivanti EPMM by midnight Sunday, May 10 after adding CVE-2026-6973 to its list of vulnerabilities exploited in attacks....
CISA KEV listing and FCEB patch order for Ivanti EPMM
Public Sector Action
H score40
First: 08.04.2026 21:15
Last: 08.04.2026 21:15
Sources 1
About this happening:
CISA added CVE-2026-1340 to the KEV Catalog and ordered FCEB agencies to patch Ivanti Endpoint Manager Mobile (EPMM) by Saturday midnight, April 11, forcin...
CISA KEV listing and FCEB patch order for Ivanti EPMM
Public Sector ActionAbout this happening: CISA added CVE-2026-1340 to the KEV Catalog and ordered FCEB agencies to patch Ivanti Endpoint Manager Mobile (EPMM) by Saturday midnight, April 11, forcin...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/Mitigation
H score44
First: 25.03.2026 17:52
Last: 25.03.2026 17:52
Sources 1
About this happening:
Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Cloud Software Group NetScaler urgent remediation advisory
Advisory/MitigationAbout this happening: Cloud Software Group issued urgent remediation guidance for NetScaler ADC and NetScaler Gateway, telling affected customers to install updated versions as soon as poss...
Ivanti Endpoint Manager (EPM) authentication bypass (CVE-2026-1603)
Vulnerability
H score71
First: 10.03.2026 13:36
Last: 10.03.2026 13:36
Sources 1
About this happening:
A high-severity flaw in Ivanti Endpoint Manager (EPM) is now actively exploited, putting remote unauthenticated attackers in position to bypass authentication...
Ivanti Endpoint Manager (EPM) authentication bypass (CVE-2026-1603)
VulnerabilityAbout this happening: A high-severity flaw in Ivanti Endpoint Manager (EPM) is now actively exploited, putting remote unauthenticated attackers in position to bypass authentication...
Ivanti Endpoint Manager unpatched RCE and privilege-escalation flaws deserialization flaw
Vulnerability
H score33
First: 10.10.2025 12:45
Last: 10.10.2025 12:45
Sources 1
About this happening:
ZDI disclosed 13 unpatched flaws in Ivanti Endpoint Manager, including a local privilege-escalation bug and 12 RCE issues that can expose affected deployments to *...
Ivanti Endpoint Manager unpatched RCE and privilege-escalation flaws deserialization flaw
VulnerabilityAbout this happening: ZDI disclosed 13 unpatched flaws in Ivanti Endpoint Manager, including a local privilege-escalation bug and 12 RCE issues that can expose affected deployments to *...
Timeline
-
09.12.2025 19:10 2 articles · 7mo ago
Ivanti discloses CVE-2025-10573 in Endpoint Manager
Initial DisclosureIvanti disclosed CVE-2025-10573 in Endpoint Manager (EPM), describing a stored XSS flaw in versions prior to 2024 SU4 SR1 that lets a remote unauthenticated attacker execute arbitrary JavaScript in an administrator session and potentially reach remote code execution. The same disclosure also said user interaction is required, that the risk is lower because EPM is not intended to be exposed online, that Ivanti released security updates for CVE-2025-13659 and CVE-2025-13662, and that Shadowserver tracks hundreds of Internet-facing EPM instances, including systems in the United States, Germany, and Japan.
Show sources
- Ivanti warns of critical Endpoint Manager code execution flaw — www.bleepingcomputer.com — 09.12.2025 19:10
- Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws — thehackernews.com — 10.12.2025 06:50