Skip to content

Ivanti warns customers of new EPM flaw enabling remote code execution

Securityaffairs.Co •Pierluigi Paganini • December 9, 2025

Ivanti warns users to address a newly disclosed Endpoint Manager vulnerability that could let attackers execute code remotely. Software firm Ivanti addressed a newly disclosed vulnerability, tracked as CVE-2025-10573 (CVSS score 9.6), in its Endpoint Manager (EPM) solution. The vulnerability is a Stored XSS that could allow a remote unauthenticated attacker to execute arbitrary “Stored […]

Extracted Entities

Companies (1)

Platforms (1)

Vulnerabilities (1)