Ivanti has disclosed a critical vulnerability (CVE-2025-10573) in its Endpoint Manager (EPM) software, which allows unauthenticated remote attackers to execute arbitrary JavaScript code via a stored cross-site scripting (XSS) attack. The flaw enables attackers to register fake managed endpoints to the EPM server, thereby injecting malicious JavaScript into the administrator web dashboard. When an administrator interacts with the compromised dashboard, the attacker can hijack the session and potentially gain full control over the EPM environment. Ivanti has released a patch (EPM 2024 SU4 SR1) to address this issue and strongly urges customers to update, especially since hundreds of EPM instances are exposed to the internet, increasing the risk of exploitation.
The vulnerability, assigned a CVSS score of 9.6, affects EPM versions 2024 SU4 and below. Security researchers at Rapid7, who discovered and reported the flaw, emphasize the urgency of patching due to the unauthenticated nature of the attack vector. Ivanti EPM is widely used for endpoint management, remote administration, and compliance, making it a high-value target for attackers. In addition to CVE-2025-10573, Ivanti has also released fixes for three other high-severity vulnerabilities in the same update cycle. Security teams are advised to apply the latest patches immediately and review the exposure of EPM instances to the internet to mitigate the risk of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2025-12-10, government cyber agencies including Canada's Cyber Centre and Singapore's CSA published advisories referencing Ivanti's December 9 security update and recommending that administrators review the vendor guidance and promptly apply the fixes. These notices reinforced the urgency of patching affected EPM deployments.
On 2025-12-09, Rapid7 and other reporting described how attackers could abuse the incomingdata web API and related CGI handler to submit malicious device scan data that is later rendered unsafely in the EPM dashboard. The write-up clarified that exploitation requires only that an administrator view the poisoned page, enabling attacker-controlled JavaScript execution.
On 2025-12-09, Ivanti publicly disclosed CVE-2025-10573, a critical unauthenticated stored XSS issue in Endpoint Manager that can let attackers poison the admin dashboard, execute JavaScript in administrator sessions, and hijack those sessions. The flaw affects versions prior to EPM 2024 SU4 SR1 and is especially risky for internet-exposed EPM instances.
On 2025-12-09, Ivanti released Endpoint Manager 2024 SU4 SR1 to fix the critical stored XSS flaw CVE-2025-10573 and three additional high-severity vulnerabilities affecting EPM 2024 SU4 and earlier. Ivanti said no active exploitation had been observed at the time of disclosure and urged customers to update immediately.
Multiple vulnerabilities in Ivanti Endpoint Manager, including CVE-2025-10573, were responsibly disclosed to Ivanti by researchers from Rapid7, watchTowr, and Trend Zero Day Initiative. Rapid7 said the disclosure process for CVE-2025-10573 was coordinated with Ivanti and included extensions to allow a comprehensive fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
indusface.com
Open sourcecomputing.co.uk
Open sourcecyber.gc.ca
Open sourcecsoonline.com
Open sourcecsa.gov.sg
Open sourcerapid7.com
Open sourcesecurityaffairs.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.