Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ivanti security patch release for CVE-2025-13659

Security Patch Release
First reported
Last updated
Happening score
H score 69
2 unique sources, 2 articles

Summary

Hide ▲

Ivanti released security updates for Endpoint Manager to address three high-severity vulnerabilities, including two flaws that could enable unauthenticated code execution on unpatched systems. The bundle includes CVE-2025-13659 and CVE-2025-13662. Exploitation still requires user interaction and contact with an untrusted core server or untrusted configuration files.

Related Happenings

Microsoft SharePoint Server actively exploited multi-CVE wave

Exploitation Wave
H score78 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: SharePoint Server exploitation wave remains active across internet-exposed on-premises instances, with CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164 used...

SAP security patch release for CVE-2026-44747

Security Patch Release
H score40 First: 14.07.2026 21:17 Last: 14.07.2026 21:17 Sources 1

About this happening: SAP's July 2026 security updates now cover multiple vulnerabilities, including a critical SAP NetWeaver Application Server ABAP flaw. The bundle includes CVE-2026-44...

Citrix security patch release for CVE-2026-13474

Security Patch Release
H score35 First: 01.07.2026 06:54 Last: 01.07.2026 06:54 Sources 1

About this happening: Citrix released security updates for NetScaler ADC and NetScaler Gateway to fix six vulnerabilities that could enable arbitrary file reads or denial of servi...

SimpleHelp security update for CVE-2026-48558

Security Patch Release
H score65 First: 15.06.2026 23:06 Last: 15.06.2026 23:06 Sources 1

About this happening: SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...

Splunk Enterprise security update for CVE-2026-20253

Security Patch Release
H score52 First: 13.06.2026 16:23 Last: 13.06.2026 16:23 Sources 1

About this happening: Splunk released security updates for CVE-2026-20253, fixing a critical Splunk Enterprise flaw that could enable unauthenticated file operations and remote code e...

Timeline

  1. 09.12.2025 19:10 2 articles · 7mo ago

    Ivanti releases Endpoint Manager fixes for critical flaws

    Mitigation Patch Update

    Ivanti warned customers to patch CVE-2025-10573 in Endpoint Manager (EPM) and released security updates for three high-severity vulnerabilities, including CVE-2025-13659 and CVE-2025-13662, which could allow unauthenticated attackers to execute arbitrary JavaScript or arbitrary code on unpatched systems when user interaction and untrusted inputs are involved. Ivanti said CVE-2025-10573 is a stored XSS flaw in versions prior to 2024 SU4 SR1, that the vulnerabilities were disclosed through its responsible disclosure program, and that it has not found evidence of exploitation in attacks. Shadowserver was tracking hundreds of Internet-facing Ivanti EPM instances, including systems in the United States, Germany, and Japan.

    Show sources