Ivanti Endpoint Manager Vulnerability Lets Remote Attacker Leak Arbitrary Data
ID: f99dcfc4-5c02-59cc-9a0d-d9aa51eef0db
STIX ID: report--f99dcfc4-5c02-59cc-9a0d-d9aa51eef0db
Feed Name: cybersecurityNews.com
Threat Score
Ivanti released security updates for Endpoint Manager (EPM 2024 SU5) addressing two vulnerabilities: CVE-2026-1603 (auth bypass, CVSS 8.6) that can leak stored credentials without authentication, and CVE-2026-1602 (SQL injection, CVSS 6.5) allowing authenticated attackers to read arbitrary database data; the flaws affect EPM 2024 SU4 SR1 and earlier, have been patched, and no active exploitation was observed before disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
