← Back to browse · API

CVE-2025-9872

Severity
HIGH
CVSS
8.8
EPSS
0.13518
Risk score
39.93
CISA KEV
No
PoC
No
Published
2025-09-09
Modified
2026-02-26
First seen
2026-08-07
Aliases
EUVD-2025-27288, GHSA-8WF3-P67R-CXMW
Products
Ivanti:Endpoint Manager patch: 2022 SU8 Security Release 2, Ivanti:Endpoint Manager patch: 2024 SU3 Security Release 1
Sources
euvd EUVD-2025-27288

Description

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

References