Vulnerabilities

High-Severity Vulnerabilities Patched by Ivanti and Zoom

Ivanti and Zoom resolved security defects that could lead to arbitrary file writes, elevation of privilege, code execution, and information disclosure.

Ivanti and Zoom resolved security defects that could lead to arbitrary file writes, elevation of privilege, code execution, and information disclosure.

Enterprise software providers Ivanti and Zoom on Tuesday announced patches for multiple vulnerabilities in their products, including high-severity issues that could lead to arbitrary file writes and code execution.

Ivanti announced fixes for three bugs in Ivanti Endpoint Manager (EMP) that could be abused by unauthenticated attackers for remote code execution, or by local attackers for privilege escalation.

Two of the flaws, tracked as CVE-2025-9713 and CVE-2025-11622, were disclosed in October, after Trend Micro’s Zero Day Initiative (ZDI) dropped 13 unpatched EMP defects.

The two previously disclosed bugs are described as a path traversal and an insecure deserialization issue. The third, CVE-2025-10918, is an insecure default permissions weakness.

Ivanti says all EMP versions before 2024 SU4 are affected by these vulnerabilities. Users are advised to update their EMP deployments as soon as possible.

“We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure,” Ivanti notes in its advisory.

Advertisement. Scroll to continue reading.

On Tuesday, Zoom published nine advisories detailing three high-severity and six medium-severity bugs in its mobile and desktop clients.

The high-severity flaws, tracked as CVE-2025-62484, CVE-2025-64741, and CVE-2025-64740, could lead to privilege escalation. The first two affect Zoom’s iOS and Android applications, while the third was identified in Zoom Workplace VDI Client for Windows.

Five of the newly resolved medium-severity issues could lead to information disclosure. They impact Zoom’s desktop applications for Linux, macOS, and Windows.

The sixth is an XSS defect in Zoom Workplace and Meeting SDK for Windows that can be exploited without authentication, impacting application integrity.

Zoom makes no mention of any of these vulnerabilities being exploited in the wild.

Related: Adobe Patches 29 Vulnerabilities

Related: Microsoft Patches Actively Exploited Windows Kernel Zero-Day

Related: SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager

Related: QNAP Patches Vulnerabilities Exploited at Pwn2Own Ireland

Related Content

Vulnerabilities

Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.

Vulnerabilities

The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.  

Vulnerabilities

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests.

Vulnerabilities

Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities.

Vulnerabilities

Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox.

Vulnerabilities

CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation.

Vulnerabilities

The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data.

Vulnerabilities

The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version