Ivanti, a leading provider of enterprise software solutions, has released critical security updates for its Endpoint Manager (EPM) products, addressing multiple vulnerabilities that could allow attackers to gain unauthorized access, escalate privileges, or disrupt systems. “We recognize the vital role that security researchers, ethical hackers, and the broader security community play in identifying and reporting vulnerabilities,” the company stated, directing users to its Vulnerability Disclosure Policy for more details. The issues were identified through the company’s responsible disclosure program, with credit given to security researchers Paul Serban of Eviden’s SEC Consult Vulnerability Lab (CVE-2025-22458) and Kevin Salapatek of Trend Micro (CVE-2025-22461) for their contributions. The security advisory details six Common Vulnerabilities and Exposures (CVEs), with severity scores ranging from 4.8 (Medium) to 8.2 (High) on the CVSS scale. With cyber threats evolving daily, this advisory serves as a critical reminder for organizations relying on Ivanti Endpoint Manager to prioritize patch management.
This Cyber News was published on cybersecuritynews.com. Publication date: Tue, 08 Apr 2025 14:50:14 +0000