Here We Go Again With Another Critical Ivanti Endpoint Manager Bug

I feel like this is groundhog day as we have yet another critical Ivanti Endpoint Manager bug to deal with.

This time around versions 2024 SU4 and below are vulnerable to stored cross-site scripting enabling attackers to remotely execute JavaScript code. Tracked as CVE-2025-10573 with a CVSS score of 9.6 out of 10. The vulnerability was patched on December 9, 2025 so you should patch all the things now.

Details can be found here: https://www.rapid7.com/blog/post/cve-2025-10573-ivanti-epm-unauthenticated-stored-cross-site-scripting-fixed/

Ensar Seker, CISO at threat intel company SOCRadar, commented:

“This latest Ivanti Endpoint Manager flaw underscores a persistent reality in enterprise environments: even widely trusted endpoint solutions can become high-value targets. While CVE-2025-10573 is ‘just’ a stored XSS vulnerability, its exploitation potential, especially when combined with social engineering, can be significant. Remote code execution via JavaScript injection is no longer theoretical in supply chain attacks; it’s become operationally viable. The fact that this requires user interaction doesn’t reduce its threat level when attackers are targeting IT admins or helpdesk interfaces. Organizations must act swiftly to patch, and more importantly, implement rigorous user interface sanitization and privilege segmentation.”

Ivanti users really need to be concerned given the rather bad track record of Ivanti products being anything but secure. That unfortunate fact makes you less secure. Which of course is a problem. One that you may not be able to rely on Ivanti to do anything about.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading