References https://nvd.nist.gov/vuln/detail/CVE-2023-32562 https://github.com/advisories/GHSA-m9h6-mxp3-hqc9 https://www.zerodayinitiative.com/advisories/ZDI-23-1117/ https://cybersecuritynews.com/ivanti-avalanche-rce-flaw/ https://malware.news/t/ivanti-avalanche-critical-buffer-overflow-vulnerabilities-cve-2023-32560/72418 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-ivanti-avalanche https://secureteam.co.uk/2023/08/22/stack-based-buffer-overflows-in-ivanti-avalanche/ https://www.fortiguard.com/encyclopedia/ips/53550 https://rivers.chaitin.cn/blog/cq949cp0lnechd242pg0 https://security.zone.ci/secnews/secpulse/308292.html https://www.unisyue.com/Service_Support/31/tzk/ldtz/1934.html https://chudypb.github.io/
Related VulnerabilitiesPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-10520: Ivanti Sentry - OS Command InjectionIvanti Sentry存在操作系统命令注入漏洞(CVE-2026-10520)Ivanti Sentry /mics/api/v2/sentry/mics-config/handleMessage 命令执行漏洞(CVE-2026-10520)Ivanti EPMM /mifs/rs/api/v2/featureusage 命令执行漏洞(CVE-2025-4427)PoCIvanti Endpoint Manager /RemoteControlAuth/api/Auth 权限绕过漏洞(CVE-2026-1603)Ivanti Endpoint Manager 权限管理不当漏洞PoCCVE-2026-1603: Ivanti Endpoint Manager - Authentication BypassIvanti Endpoint Manager Mobile /mifs/c/appstore/fob/3/5/sha256 命令执行漏洞(CVE-2026-1281/CVE-2026-1340)Ivanti Endpoint Manager Mobile 未授权 代码注入漏洞Ivanti多个产品跨站请求伪造漏洞(CVE-2025-8711)(CVE-2025-8712)Ivanti产品权限验证不足漏洞