The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Motex Lanscope Endpoint Manager, tracked as CVE-2025-61932, to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation. This flaw, which affects on-premises versions of the Lanscope Endpoint Manager client and detection agent up to version 9.4.7.1, allows attackers to execute arbitrary code by sending specially crafted packets due to improper verification of the source of communication channels. Motex has confirmed that at least one customer received a malicious packet suspected to target this vulnerability, though the scale and attribution of the attacks remain unclear.
CISA has mandated that Federal Civilian Executive Branch agencies remediate the vulnerability by November 12, 2025, and strongly recommends that private organizations also address the issue. The vulnerability has been patched in subsequent versions, including 9.3.2.7 through 9.4.7.3. Security experts emphasize the importance of prompt remediation to protect networks from ongoing exploitation attempts targeting this critical flaw.

See which actors are running it and whether you're in range.
4 events from the most recent confirmed update back to the earliest known activity.
CISA added the critical Motex Lanscope Endpoint Manager flaw CVE-2025-61932 to its Known Exploited Vulnerabilities catalog after confirming ongoing exploitation. The agency ordered U.S. federal civilian agencies to remediate the issue by 2025-11-12.
Japan's CERT Coordination Center warned of active exploitation of CVE-2025-61932 affecting domestic organizations. It also published attacker IP addresses and command-and-control infrastructure associated with a backdoor used in the attacks.
Motex reported exploit attempts against Japan-based customers and confirmed the flaw was being exploited in the wild. The company released fixed versions for affected client-side components, said the management server software and SaaS/cloud version were not affected, and advised customers to update client PCs.
JPCERT/CC said CVE-2025-61932 in Motex Lanscope Endpoint Manager On-Premise has been exploited as a zero-day since April 2025. The attacks targeted customer environments in Japan and involved specially crafted packets sent to TCP port 443 against affected client components.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourcesocradar.io
Open sourcehelpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.