Ivanti EPM Flaw: A Comedy of Errors with Serious Remote Code Risks!

Ivanti warns users of a new Endpoint Manager flaw, CVE-2025-10573, with a CVSS score of 9.6. This vulnerability allows remote code execution via stored XSS, letting attackers hijack admin sessions. Rapid7 researchers urge immediate patching to prevent becoming the accidental star of a cybersecurity horror-comedy.

Pro Dashboard

Hot Take:

Looks like Ivanti’s Endpoint Manager has a new party trick, and it’s not the kind of magic we want to see. With a stored XSS vulnerability that could allow attackers to take over admin sessions, it’s like inviting hackers to a virtual jamboree! Time to patch up that party crasher before things get out of hand.

Key Points:

  • The newly disclosed vulnerability, CVE-2025-10573, scores a 9.6 on the CVSS scale – high enough to make your cybersecurity team break out in a sweat.
  • This stored XSS flaw enables remote code execution by an unauthenticated attacker, who can exploit it by registering fake endpoints and injecting malicious JavaScript.
  • Ivanti Endpoint Manager versions prior to 2024 SU4 SR1 are affected, so admins should scramble for the nearest patch.
  • The exploit takes advantage of an unauthenticated incomingdata API that processes unsanitized device scan data, making it ripe for script injection.
  • No known wild exploits yet, but with past EPM vulnerabilities making CISA’s KEV catalog, it’s only a matter of time before someone tries their luck.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?