
Ivanti Patches Critical Stored XSS Vulnerability in Endpoint Manager (CVE-2025-10573)
Ivanti has released a patch for a critical vulnerability in its Endpoint Manager (EPM) software, tracked as CVE-2025-10573 with a CVSS score of 9.6. This vulnerability is a Stored Cross-Site Scripting (XSS) flaw that allows unauthenticated attackers to execute arbitrary code remotely. The issue affects users of Ivanti EPM, a solution designed for managing and securing endpoints within an organization. Stored XSS vulnerabilities are particularly dangerous because malicious scripts are permanently stored on the target server. When a user accesses the affected page, the script is executed, potentially leading to the execution of malicious commands on the target system. The high CVSS score of 9.6 underscores the severity of this vulnerability and the urgent need for remediation. The potential impact of this vulnerability includes the execution of malicious commands on target systems, which can lead to data theft, installation of malware, or further lateral movement within the network. Given that the vulnerability can be exploited by unauthenticated attackers, it poses a significant risk to organizations using Ivanti EPM. Organizations should prioritize applying the patch immediately to mitigate the risk associated with this vulnerability. Additionally, they should monitor their systems for any signs of exploitation. This incident highlights the importance of regular software updates and robust vulnerability management practices. It also underscores the need for a layered defense strategy, including network segmentation and endpoint protection, to limit the impact of such vulnerabilities.