References https://nvd.nist.gov/vuln/detail/CVE-2025-8712 https://hub.ivanti.com/s/article/September-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-and-Neurons-for-Secure-Access-Multiple-CVEs https://www.hkcert.org/security-bulletin/ivanti-products-multiple-vulnerabilities_20250910 https://www.doxnet.com/articles/a-vulnerability-in-ivanti-products-identified-sept-9-2025 https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-ivanti-products-could-allow-for-remote-code-execution_2025-084 https://threatprotect.qualys.com/2025/09/11/ivanti-september-security-updates-address-multiple-vulnerabilities-in-popular-products/ https://www.tenable.com/plugins/nessus/264601 https://strobes.co/vi/cve/CVE-2025-8712 https://gbhackers.com/multiple-vulnerabilities-discovered/ https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-8712
Related VulnerabilitiesPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-10520: Ivanti Sentry - OS Command InjectionIvanti Sentry存在操作系统命令注入漏洞(CVE-2026-10520)Ivanti Sentry /mics/api/v2/sentry/mics-config/handleMessage 命令执行漏洞(CVE-2026-10520)Ivanti EPMM /mifs/rs/api/v2/featureusage 命令执行漏洞(CVE-2025-4427)PoCIvanti Endpoint Manager /RemoteControlAuth/api/Auth 权限绕过漏洞(CVE-2026-1603)Ivanti Endpoint Manager 权限管理不当漏洞PoCCVE-2026-1603: Ivanti Endpoint Manager - Authentication BypassIvanti Endpoint Manager Mobile /mifs/c/appstore/fob/3/5/sha256 命令执行漏洞(CVE-2026-1281/CVE-2026-1340)Ivanti Endpoint Manager Mobile 未授权 代码注入漏洞Ivanti多个产品跨站请求伪造漏洞(CVE-2025-8711)Ivanti Pulse Connect Secure VPN /dana-na/auth/saml-sso.cgi XML 外部实体注入漏洞(CVE-2024-22024)