Critical Remote Code Execution Vulnerability in Ivanti Endpoint Manager (CVE-2025-10573)
Ivanti has disclosed a critical vulnerability (CVE-2025-10573) in its Endpoint Manager (EPM) software, which allows unauthenticated remote attackers to execute arbitrary JavaScript code via a stored cross-site scripting (XSS) attack. The flaw enables attackers to register fake managed endpoints to the EPM server, thereby injecting malicious JavaScript into the administrator web dashboard. When an administrator interacts with the compromised dashboard, the attacker can hijack the session and potentially gain full control over the EPM environment. Ivanti has released a patch (EPM 2024 SU4 SR1) to address this issue and strongly urges customers to update, especially since hundreds of EPM instances are exposed to the internet, increasing the risk of exploitation.
The vulnerability, assigned a CVSS score of 9.6, affects EPM versions 2024 SU4 and below. Security researchers at Rapid7, who discovered and reported the flaw, emphasize the urgency of patching due to the unauthenticated nature of the attack vector. Ivanti EPM is widely used for endpoint management, remote administration, and compliance, making it a high-value target for attackers. In addition to CVE-2025-10573, Ivanti has also released fixes for three other high-severity vulnerabilities in the same update cycle. Security teams are advised to apply the latest patches immediately and review the exposure of EPM instances to the internet to mitigate the risk of compromise.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
National cyber agencies issue follow-on advisories urging patching
On 2025-12-10, government cyber agencies including Canada's Cyber Centre and Singapore's CSA published advisories referencing Ivanti's December 9 security update and recommending that administrators review the vendor guidance and promptly apply the fixes. These notices reinforced the urgency of patching affected EPM deployments.
Technical details published for CVE-2025-10573 exploitation path
On 2025-12-09, Rapid7 and other reporting described how attackers could abuse the incomingdata web API and related CGI handler to submit malicious device scan data that is later rendered unsafely in the EPM dashboard. The write-up clarified that exploitation requires only that an administrator view the poisoned page, enabling attacker-controlled JavaScript execution.
Ivanti discloses critical CVE-2025-10573 in Endpoint Manager
On 2025-12-09, Ivanti publicly disclosed CVE-2025-10573, a critical unauthenticated stored XSS issue in Endpoint Manager that can let attackers poison the admin dashboard, execute JavaScript in administrator sessions, and hijack those sessions. The flaw affects versions prior to EPM 2024 SU4 SR1 and is especially risky for internet-exposed EPM instances.
Ivanti releases EPM 2024 SU4 SR1 to patch four vulnerabilities
On 2025-12-09, Ivanti released Endpoint Manager 2024 SU4 SR1 to fix the critical stored XSS flaw CVE-2025-10573 and three additional high-severity vulnerabilities affecting EPM 2024 SU4 and earlier. Ivanti said no active exploitation had been observed at the time of disclosure and urged customers to update immediately.
Researchers responsibly disclose Ivanti EPM vulnerabilities to Ivanti
Multiple vulnerabilities in Ivanti Endpoint Manager, including CVE-2025-10573, were responsibly disclosed to Ivanti by researchers from Rapid7, watchTowr, and Trend Zero Day Initiative. Rapid7 said the disclosure process for CVE-2025-10573 was coordinated with Ivanti and included extensions to allow a comprehensive fix.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
9 references tracked. Mallory keeps watching after this page renders.
CVE-2025-10573: Critical Unauthenticated Stored XSS in Ivanti Endpoint Manager
indusface.com
Open sourceIvanti patches Endpoint Manager flaw allowing remote code execution
computing.co.uk
Open sourceCritical Vulnerability in Ivanti Endpoint Manager
csa.gov.sg
Open sourceIvanti security advisory (AV25-824)
cyber.gc.ca
Open sourceHundreds of Ivanti EPM systems exposed online as critical flaw patched
csoonline.com
Open sourceIvanti Security Update: Patch for Code Execution Vulnerabilities in Endpoint Manager
cybersecuritynews.com
Open sourceCVE-2025-10573: Ivanti EPM Unauthenticated Stored Cross-Site Scripting (Fixed)
rapid7.com
Open sourceIvanti warns customers of new EPM flaw enabling remote code execution
securityaffairs.com
Open sourceIvanti warns of critical Endpoint Manager code execution flaw
bleepingcomputer.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


