Multiple Endpoint Manager bugs patched by Ivanti, including remote auth bypass
ID: 4c615b79-7770-5bfd-b8d2-01de5ab698af
STIX ID: report--4c615b79-7770-5bfd-b8d2-01de5ab698af
Feed Name: Security Affairs
Threat Score
Ivanti released patches for multiple Endpoint Manager vulnerabilities — notably a remote unauthenticated authentication bypass (CVE-2026-1603, CVSS 8.6) that could leak stored credentials, an SQL injection (CVE-2026-1602, CVSS 6.5), and a stored XSS (CVE-2025-10573, CVSS 9.6); Trend Micro’s ZDI reported the issues and Ivanti says EPM 2024 SU5/SU4 SR1 address the flaws with no known in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
