logo

Ivanti Endpoint Manager Vulnerability Lets Remote Attacker Leak Arbitrary Data

ID: f99dcfc4-5c02-59cc-9a0d-d9aa51eef0db

STIX ID: report--f99dcfc4-5c02-59cc-9a0d-d9aa51eef0db

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-02-10

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Ivanti released security updates for Endpoint Manager (EPM 2024 SU5) addressing two vulnerabilities: CVE-2026-1603 (auth bypass, CVSS 8.6) that can leak stored credentials without authentication, and CVE-2026-1602 (SQL injection, CVSS 6.5) allowing authenticated attackers to read arbitrary database data; the flaws affect EPM 2024 SU4 SR1 and earlier, have been patched, and no active exploitation was observed before disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.