Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

High-Risk Ivanti EPM Vulnerability Opens Door to Admin Session Hijacking

## Overview of Cross-Site Scripting Vulnerability in Ivanti Endpoint Manager

Overview of Cross-Site Scripting Vulnerability in Ivanti Endpoint Manager

A critical stored cross-site scripting (XSS) vulnerability has been identified in Ivanti Endpoint Manager (EPM). This vulnerability, known as CVE-2025-10573, carries a CVSS score of 9.6 and affects all versions below EPM 2024 SU4 SR1. The vulnerability allows unauthenticated attackers to hijack administrator sessions by injecting malicious JavaScript into the management dashboard. This poses a significant threat to enterprise environments managing numerous endpoints.

Ivanti EPM is widely used for endpoint management and vulnerability scanning. The vulnerability arises from an unauthenticated entry point that allows attackers to inject malicious payloads into the administrator dashboard. This issue is due to unsafe handling of device scan data submitted via the '/incomingdata' web API, which lacks proper input validation and output encoding.

Attackers can submit crafted device requests containing XSS payloads to the exposed 'postcgi.exe' CGI binary. The malicious data is automatically processed and stored in the EPM database. When administrators access dashboard pages that display device information, the unencoded XSS payloads execute in their browser context, allowing attackers to gain control over the administrator's authenticated session.

This vulnerability affects versions Ivanti EPM 11.0.6 and below EPM 2024 SU4. The attack does not require valid credentials or prior system access; network connectivity to the EPM web service suffices.

A critical stored cross-site scripting (XSS) vulnerability has been identified in Ivanti Endpoint Manager (EPM).
John Mason · Thehackingpost

Ivanti has released version EPM 2024 SU4 SR1 on December 9, 2025, which addresses CVE-2025-10573. Organizations using affected versions should prioritize upgrading to mitigate the vulnerability due to the high privilege level of compromised administrator accounts.

Rapid7 will provide authenticated checks for this vulnerability through Exposure Command, InsightVM, and Nexpose on December 9, 2025, to help organizations identify vulnerable instances.

The vulnerability was discovered by Ryan Emmons, Staff Security Researcher at Rapid7, with close coordination between Rapid7 and the Ivanti security team to ensure timely patching. Ivanti has acknowledged the critical nature of the vulnerability and appreciates Rapid7's collaborative approach to responsible disclosure.

Advertisement

Organizations utilizing Ivanti EPM should treat this vulnerability as critical and apply patches immediately. The attack requires no authentication and targets administrator accounts with full system privileges, making compromise particularly damaging. Implementing network segmentation to restrict access to the EPM web interface and monitoring device scan submissions can provide temporary mitigation while patches are deployed.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories