The Cybersecurity and Infrastructure Security Agency (CISA) updated its KEV catalog on March 10, 2025, to include three newly identified vulnerabilities in Ivanti Endpoint Manager (EPM), a widely used enterprise software for managing endpoints. Given Ivanti EPM’s role in managing enterprise endpoints, leaks of sensitive data could lead to broader network compromises, making timely action critical. Each flaw enables a remote, unauthenticated attacker to access sensitive files by manipulating file paths, potentially exposing configuration data, credentials, or other critical information. With a three-week remediation window for federal agencies, enterprises using Ivanti EPM should act swiftly to mitigate risks and prevent potential data leaks from escalating into larger breaches. The KEV catalog tracks vulnerabilities actively exploited in the wild, urging organizations to prioritize remediation to safeguard critical systems. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. While it’s unknown if these vulnerabilities are tied to ransomware campaigns, their presence in the KEV catalog indicates confirmed exploitation in real-world scenarios.
This Cyber News was published on cybersecuritynews.com. Publication date: Mon, 10 Mar 2025 21:40:05 +0000