logo

Multiple Endpoint Manager bugs patched by Ivanti, including remote auth bypass

ID: 4c615b79-7770-5bfd-b8d2-01de5ab698af

STIX ID: report--4c615b79-7770-5bfd-b8d2-01de5ab698af

Feed Name: Security Affairs

Threat Score
60/100

Date Published: 2026-02-12

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Ivanti released patches for multiple Endpoint Manager vulnerabilities — notably a remote unauthenticated authentication bypass (CVE-2026-1603, CVSS 8.6) that could leak stored credentials, an SQL injection (CVE-2026-1602, CVSS 6.5), and a stored XSS (CVE-2025-10573, CVSS 9.6); Trend Micro’s ZDI reported the issues and Ivanti says EPM 2024 SU5/SU4 SR1 address the flaws with no known in-the-wild exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.