CVE-2024-13159Active Exploitation(ivanti / endpoint_manager)

LOWCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for ivanti endpoint_manager systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

3.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-31. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-36

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager

Threat summary

  • Active exploitation appears in 3 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 3 signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
endpoint_manager

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-02: 3Active Exploitation · 2026-05-02: 305-02
Signal classification2 categories
Active Exploitation
266.7%
Exploit
133.3%
Referenced assets1 URL
Full discourse3 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Vendor. CISA added CVE-2024-13159 to the Known Exploited Vulnerabilities (KEV) catalog, signaling in-the-wild exploitation and setting a federal remediation due date of

    Post summary

    CISA identifies CVE-2024-13159 as actively exploited, adding it to the KEV catalog and urging federal remediation.

    1000032
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-13159. What happened CISA added CVE-2024-13159 to the Known Exploited Vulnerabilities (KEV) catalog, signaling in-the-wild exploitation and setting a federal remediation due date of 2025-03-31 CISA KEV.

    Post summary

    CISA has categorized CVE-2024-13159 as an actively exploited vulnerability, setting a federal remediation deadline of March 31, 2025.

    1000042
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Exploit

    https://research.lyrie.ai/research/active-exploit-cve-2024-13159-endpoint-manager-epm #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The link references a report of an active exploit against CVE‑2024‑13159 in Endpoint Manager EPM; the text confirms claim of in‑the‑wild activity but provides no PoC, exploit code details, patch information, or technical specifics.

    0000035
    152 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager---
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2024--

Explore more