Loading
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.
Use CWE-913, Ivanti vendor hub and Endpoint Manager product page to widen CVE-2025-13659 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-1603, CVE-2025-10573 and CVE-2025-13662 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 27th, 2026.