Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
High-Severity Vulnerabilities Patched by Ivanti and Zoom

High-Severity Vulnerabilities Patched by Ivanti and Zoom

Posted on November 12, 2025November 12, 2025 By CWS

Enterprise software program suppliers Ivanti and Zoom on Tuesday introduced patches for a number of vulnerabilities of their merchandise, together with high-severity points that might result in arbitrary file writes and code execution.

Ivanti introduced fixes for 3 bugs in Ivanti Endpoint Supervisor (EMP) that might be abused by unauthenticated attackers for distant code execution, or by native attackers for privilege escalation.

Two of the issues, tracked as CVE-2025-9713 and CVE-2025-11622, had been disclosed in October, after Pattern Micro’s Zero Day Initiative (ZDI) dropped 13 unpatched EMP defects.

The 2 beforehand disclosed bugs are described as a path traversal and an insecure deserialization challenge. The third, CVE-2025-10918, is an insecure default permissions weak spot.

Ivanti says all EMP variations earlier than 2024 SU4 are affected by these vulnerabilities. Customers are suggested to replace their EMP deployments as quickly as potential.

“We’re not conscious of any clients being exploited by these vulnerabilities on the time of disclosure,” Ivanti notes in its advisory.

On Tuesday, Zoom revealed 9 advisories detailing three high-severity and 6 medium-severity bugs in its cellular and desktop shoppers.

The high-severity flaws, tracked as CVE-2025-62484, CVE-2025-64741, and CVE-2025-64740, might result in privilege escalation. The primary two have an effect on Zoom’s iOS and Android functions, whereas the third was recognized in Zoom Office VDI Shopper for Home windows.Commercial. Scroll to proceed studying.

5 of the newly resolved medium-severity points might result in data disclosure. They affect Zoom’s desktop functions for Linux, macOS, and Home windows.

The sixth is an XSS defect in Zoom Office and Assembly SDK for Home windows that may be exploited with out authentication, impacting software integrity.

Zoom makes no point out of any of those vulnerabilities being exploited within the wild.

Associated: Adobe Patches 29 Vulnerabilities

Associated: Microsoft Patches Actively Exploited Home windows Kernel Zero-Day

Associated: SAP Patches Vital Flaws in SQL Wherever Monitor, Answer Supervisor

Associated: QNAP Patches Vulnerabilities Exploited at Pwn2Own Eire

Security Week News Tags:HighSeverity, Ivanti, Patched, Vulnerabilities, Zoom

Post navigation

Previous Post: [Webinar] Learn How Leading Security Teams Reduce Attack Surface Exposure with DASR
Next Post: Microsoft Investigating Teams Issue that Disables Users from Opening Apps

Related Posts

Destructive Russian Cyberattacks on Ukraine Expand to Grain Sector Destructive Russian Cyberattacks on Ukraine Expand to Grain Sector Security Week News
240,000 Impacted by Data Breach at Eyecare Tech Firm Ocuco 240,000 Impacted by Data Breach at Eyecare Tech Firm Ocuco Security Week News
Organizations Warned of Exploited Meteobridge Vulnerability Organizations Warned of Exploited Meteobridge Vulnerability Security Week News
Korean Air Data Compromised in Oracle EBS Hack Korean Air Data Compromised in Oracle EBS Hack Security Week News
Google Revamps Bug Bounties as AI Transforms Security Google Revamps Bug Bounties as AI Transforms Security Security Week News
SAP Addresses Critical Vulnerabilities in S/4HANA SAP Addresses Critical Vulnerabilities in S/4HANA Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark