Back Computing Ivanti patches Endpoint Manager flaw allowing remote code execution
Ivanti is urging customers to apply newly released patches after disclosing a critical security vulnerability in its widely used Endpoint Manager (EPM) platform.
The flaw could enable unauthenticated attackers to remotely execute code.
Businesses use Ivanti’s EPM technology for remote administration, vulnerability scanning and compliance oversight of employee devices, while admins use it to control endpoints and install software.
These factors make it a high-value target for cybercriminals.
The flaw, tracked as CVE-2025-10573, enables low-complexity cross-site scripting (XSS) attacks that require minimal user interaction to succeed.
According to Rapid7 staff security researcher Ryan Emmons, who discovered and reported the bug in August, remote unauthenticated actors can exploit the issue to execute arbitrary JavaScript code.
"An attacker with unauthenticated access to the primary EPM web service can join fake managed endpoints to the EPM server in order to poison the administrator web dashboard with malicious JavaScript," Emmons explained .
"When an Ivanti EPM administrator views one of the poisoned dashboard interfaces during normal usage, that passive user interaction will trigger client-side JavaScript execution, resulting in the attacker gaining control of the administrator's session."
Ivanti has released a fix in EPM version 2024 SU4 SR1 and said exposure should be limited, as the platform is not intended to be accessible from the internet.
However, telemetry from the Shadowserver Foundation suggests the risk may be more widespread than Ivanti believes: hundreds of internet-facing instances are currently visible online, primarily in the United States (569), Germany (109) and Japan (104).
Ivanti has also pushed out patches for three additional high-severity vulnerabilities. Two of these, CVE-2025-13659 and CVE-2025-13662, could allow remote code execution without authentication.
Fortunately, exploitation would still require targets to interact with untrusted servers or import malicious configuration files.
"We are not aware of any customers being exploited by these vulnerabilities prior to public disclosure," Ivanti said, crediting the findings to responsible disclosure efforts.
The company reaffirmed its focus on product security and praised the wider cybersecurity community for its collaboration.
“We recognise the vital role that security researchers, ethical hackers and the broader security community play in identifying and reporting vulnerabilities,” it said.
Attackers are increasingly targeting Ivanti’s EPM platform. CISA has added four critical EPM flaws (CVE-2024-13159, CVE-2024-13160, CVE-2024-13161 and CVE-2024-29824) to its catalogue of exploited vulnerabilities this year; and Ivanti itself patched a critical vulnerability, CVE-2025-0282, that was actively exploited in the wild to compromise Connect Secure appliances in January.
In a separate advisory, Fortinet announced critical patches addressing improper verification of cryptographic signatures in multiple products, including FortiOS, FortiWeb, FortiProxy and FortiSwitchManager.
The flaws, CVE-2025-59718 and CVE-2025-59719 , carry CVSS scores of 9.8 and could enable attackers to bypass FortiCloud SSO authentication using manipulated SAML messages.
Fortunately, the vulnerable FortiCloud SSO login feature is not enabled by default and is only active if administrators choose to allow it when registering a device with FortiCare.
As a temporary mitigation, Fortinet recommends disabling FortiCloud SSO login until systems can be fully updated.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
