Latest Product Updates and Feature Enhancements on Ivanti Xtraction

 

Fortinet, Ivanti, Nvidia Release Security Updates

Ivanti released security updates addressing multiple high- and medium-severity vulnerabilities in its products, including Endpoint Manager, Connect Secure, Policy Secure, ZTA Gateways, and Neurons fo...r Secure Access. The updates fix issues like insufficient filename validation and missing authorization, which could lead to code execution and unauthorized actions.

Read more →
 

Fortinet, Ivanti Release August 2025 Security Patches

Ivanti released August 2025 security patches addressing vulnerabilities in Ivanti Avalanche, Ivanti Virtual Application Delivery Control, and Ivanti Connect Secure. These updates fix high-severity re...mote code execution and denial-of-service vulnerabilities. Ivanti advises customers to apply patches promptly to prevent potential exploitation.

Read more →
 

Ivanti Zero-Days Exploited to Drop MDifyLoader and Launch In-Memory Cobalt Strike Attacks

Ivanti's Connect Secure appliances were targeted by cyberattacks exploiting vulnerabilities CVE-2025-0282 and CVE-2025-22457, leading to the deployment of MDifyLoader and in-memory Cobalt Strike atta...cks. These flaws, patched by Ivanti in early 2025, allowed unauthorized remote code execution and arbitrary code execution. Ivanti emphasizes the importance of staying updated to protect against such threats.

Read more →
 

Ivanti Endpoint Mobile Manager customers exploited via chained vulnerabilities

Ivanti has confirmed that hackers exploited vulnerabilities CVE-2025-4427 and CVE-2025-4428 in its Endpoint Mobile Manager (EPMM) software, enabling remote code execution. Ivanti urges all customers ...to upgrade to the latest fixed version. The flaws stem from issues in integrated open-source libraries, raising broader security concerns for enterprise mobile device management.

Read more →
 

Ivanti Endpoint Mobile Manager customers exploited via chained vulnerabilities - Yahoo Finance

Ivanti has released urgent security updates for its Endpoint Manager Mobile (EPMM) platform after a critical zero-day vulnerability was discovered and actively exploited by attackers. The flaw allowe...d unauthorized access to sensitive data and system controls. Governments and enterprises are rapidly deploying the patch to protect mobile device management infrastructure and prevent further breaches.

Read more →
 

Ivanti Patches Two EPMM Zero-Days Exploited to Hack Customers

Ivanti Patches Two EPMM Zero-Days Exploited to Hack Customers

Read more →
 

Ivanti Patches EPMM Vulnerabilities Exploited for Remote Code Execution in Limited Attacks

Ivanti released security patches for Endpoint Manager Mobile (EPMM) to address two actively exploited vulnerabilities: CVE-2025-4427 (authentication bypass) and CVE-2025-4428 (remote code execution).... Attackers could chain these flaws for unauthenticated code execution. Updates are available for versions 11.12.0.5, 12.3.0.2, 12.4.0.2, and 12.5.0.1. Ivanti credited CERT-EU for discovery and confirmed limited exploitation.

Read more →
 

Chinese Espionage Group Targeting Legacy Ivanti VPN Devices

A Chinese espionage group is targeting legacy Ivanti VPN devices, highlighting cybersecurity risks and vulnerabilities associated with these devices.

Read more →
 

Ivanti Connect Secure RCE Vulnerability Actively Exploited in the Wild ...

Ivanti disclosed a critical vulnerability, CVE-2025-22457, affecting its Connect Secure and other products, actively exploited since March 2025. The flaw allows remote code execution and has been use...d by the UNC5221 group for cyberattacks. Ivanti released patches for affected versions, urging immediate updates to mitigate risks. This incident highlights the need for robust cybersecurity measures and timely patching.

Read more →
 

CISA Adds Actively Exploits Ivanti Connect Secure Vulnerability in ...

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability (CVE-2025-22457) in Ivanti Connect Secure to its Known Exploited Vulnerabilities Catalog. This vuln...erability allows remote code execution and has been actively exploited since March 2025. Ivanti has released patches for Connect Secure, with additional patches for Policy Secure and ZTA Gateways due in April. Organizations are urged to apply these updates promptly to mitigate risks.

Read more →
 

TRAILBLAZE & BRUSHFIRE Malware Deployed in Ivanti Apps / Services

Ivanti disclosed a critical security vulnerability in its Connect Secure VPN appliances, which has been patched. The flaw, CVE-2025-22457, allowed remote code execution but was fixed in version 22.7R...2.6.

Read more →
 

CISA Flags Critical Ivanti Vulnerabilities Actively Exploited In The Wild

CISA has identified critical vulnerabilities in Ivanti products that are being actively exploited, posing significant security risks.

Read more →
 

Critical Ivanti Vulnerabilities Addressed with Latest Patch - The Cyber Express

Ivanti has released a patch to fix critical vulnerabilities in its software, enhancing security for users.

Read more →
 

Ivanti Patches Critical Vulnerabilities in Endpoint Manager - SecurityWeek

Ivanti has released patches to fix critical vulnerabilities in its Endpoint Manager software to enhance security.

Read more →
 

Ivanti zero-day patching increases amid ongoing attacks

Organizations are quickly patching Ivanti's zero-day vulnerability, CVE-2025-0282, after it was exploited by Chinese hackers.

Read more →
 

Ivanti warns critical RCE flaw in Connect Secure exploited as zero - day

Ivanti warns of a critical remote code execution flaw in Connect Secure, which has been exploited as a zero-day vulnerability.

Read more →
 

Ivanti warns of new Connect Secure flaw used in zero - day attacks

Ivanti warns of a Connect Secure vulnerability, CVE-2025-0282, exploited in zero-day attacks to install malware on appliances.

Read more →
 

Ivanti Discloses Exploitation Of Critical VPN Vulnerability

Ivanti disclosed a critical zero-day vulnerability in its Connect Secure VPN, which has been exploited, and a high-severity flaw that hasn't been exploited yet. Customers are advised to use the Integ...rity Checker Tool and upgrade if scans are clean.

Read more →
 

Ivanti Issues Critical Security Updates for CSA and Connect Secure Vulnerabilities - The Hacker News

Ivanti released important security updates to fix vulnerabilities in their CSA and Connect Secure products.

Read more →
 

Ivanti Launches Neurons for App Control Solution to Boost Endpoint Security - Business Wire

Ivanti launches Neurons for App Control to enhance endpoint security.

Read more →
Show More

Strategic Partnerships and Integrations of Ivanti Xtraction

 

Ivanti Partners with Project Hosts to Accelerate FedRAMP High and DoD IL5 Compliance Journey

Ivanti has partnered with Project Hosts to help accelerate their journey towards achieving FedRAMP High and DoD IL5 compliance.

Read more →

Leadership and Executive Team Updates at Ivanti Xtraction

 

Karl Triebes Joins Ivanti as Chief Product Officer - Dark Reading

Karl Triebes has joined Ivanti as the Chief Product Officer.

Read more →
 

Seasoned Tech Leader Karl Triebes Joins Ivanti as Chief Product Officer

Karl Triebes has joined Ivanti as the Chief Product Officer.

Read more →
 

Seasoned Tech Leader Karl Triebes Joins Ivanti as Chief Product Officer - Business Wire

Karl Triebes, a seasoned tech leader, has joined Ivanti as the Chief Product Officer.

Read more →
 

Ivanti Names Software Industry Leader Dennis Kozak as CEO - Business Wire

Ivanti has appointed Dennis Kozak as its new CEO.

Read more →

Other Related News and Updates from Ivanti Xtraction

 

Ivanti Patches 50 Vulnerabilities Across Several Products - IT Security News

Ivanti addresses 50 vulnerabilities across various products, enhancing security in Endpoint Manager, Avalanche, and others.

Read more →
 

Two currently (old) exploited Ivanti vulnerabilities, (Sun, Oct 27th) - IT Security News

Ivanti products have ongoing vulnerabilities exploited by hackers, emphasizing the need for consistent patching or disabling to enhance security.

Read more →