← Back to browse · API

CVE-2025-9712

Severity
HIGH
CVSS
8.8
EPSS
0.20531
Risk score
42.39
CISA KEV
No
PoC
No
Published
2025-09-09
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-27416, GHSA-F42Q-G7JG-2P77
Products
Ivanti:Endpoint Manager patch: 2022 SU8 Security Release 2, Ivanti:Endpoint Manager patch: 2024 SU3 Security Release 1
Sources
euvd EUVD-2025-27416

Description

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

References