• News/
  • https://www.bleepingcomputer.com/news/security/ivanti-warns-of-critical-endpoint-manager-code-execution-flaw/

Ivanti warns of critical Endpoint Manager code execution flaw

BleepingComputer
·
Sergiu Gatlan
·
Published Dec 9, 2025
·
Updated

American IT software company Ivanti warned customers today to patch a newly disclosed vulnerability in its Endpoint Manager (EPM) solution that could allow attackers to execute code remotely. Ivanti delivers system and IT asset management solutions to over 40,000 companies via a network of more than 7,000 organizations worldwide. The company's EPM software is an all-in-one endpoint management tool for managing client devices across popular platforms, including Windows, macOS, Linux, Chrome OS, and IoT. Tracked as CVE-2025-10573, this critical security flaw can be exploited by remote, unauthenticated threat actors to execute arbitrary JavaScript code through low-complexity cross-site scripting attacks that require user interaction. "An attacker with unauthenticated access to the primary EPM web service can join fake managed endpoints to the EPM server in order to poison the administrator web dashboard with malicious JavaScript," explained Rapid7 staff security researcher Ryan Emmons, who reported the vulnerability in August. "When an Ivanti EPM administrator views one of the poisoned dashboard interfaces during normal usage, that passive user interaction will trigger client-side JavaScript execution, resulting in the attacker gaining control of the administrator’s session." Ivanti released EPM version EPM 2024 SU4 SR1 to address the issue, and noted that the risk of this vulnerability should be significantly reduced because the Ivanti EPM solution is not intended to be expose...

Read full article

Affected Software

1 affected component
Ivanti Endpoint Manager
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in Ivanti's Endpoint Manager that could allow for remote code execution.

2

What security implications are discussed?

The vulnerability poses a significant risk as it enables attackers to execute arbitrary code on affected systems.

3

What products or software are affected?

The affected product is Ivanti Endpoint Manager (EPM).

4

What should customers do in response to this vulnerability?

Customers are urged to apply patches as soon as possible to mitigate the risk associated with the vulnerability.

5

Who issued the warning about the vulnerability?

The warning was issued by Ivanti, an American IT software company.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203