CVE-2024-13160Active Exploitation(ivanti / endpoint_manager)

HIGHCVSS 7.5 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for ivanti endpoint_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

7.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-31. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-36

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
endpoint_manager

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-02: 3PoC Mentioned / Linked · 2026-05-02: 1Exploit Tool / Code · 2026-05-02: 1Active Exploitation · 2026-05-02: 3Technical Details · 2026-05-02: 105-02
Signal classification1 categories
Active Exploitation
3100.0%
Referenced assets1 URL
Full discourse3 posts
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    Vendor. CISA added Ivanti Endpoint Manager (EPM) CVE-2024-13160 to the Known Exploited Vulnerabilities catalog on 2025-03-10, signaling confirmed in-the-wild exploitati

    Post summary

    CISA confirmed that CVE‑2024‑13160 in Ivanti Endpoint Manager is being exploited in the wild.

    1000049
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-13160. What happened CISA added Ivanti Endpoint Manager (EPM) CVE-2024-13160 to the Known Exploited Vulnerabilities catalog on 2025-03-10, signaling confirmed in-the-wild exploitation and a federal remediation due date of 2025-03-31 CISA KEV.

    Post summary

    CVE-2024-13160 is confirmed to be exploited in the wild, with a federal remediation deadline set.

    1000058
    152 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-13160-endpoint-manager-epm #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked research confirms that CVE-2024-13160 in Endpoint Manager is being actively exploited, providing PoC and exploit details. Security teams should treat this as an immediate threat until a vendor patch is released.

    0000032
    152 followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager---
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2022--
Appivantiendpoint_manager2024--

Explore more