Ivanti Endpoint Manager Flaw Enables Remote Data Exposure
ID: 6578ea04-d284-57b8-99ec-f22b9bcd9bab
STIX ID: report--6578ea04-d284-57b8-99ec-f22b9bcd9bab
Feed Name: GBHackers
Threat Score
**Ivanti issues emergency patch for EPM** — A high-severity authentication-bypass (CVE-2026-1603, CVSS 8.6) and a medium SQL injection (CVE-2026-1602, CVSS 6.5) were disclosed; administrators should update to 2024 SU5 immediately as these flaws can expose stored credentials and enable data leakage, though Ivanti reports no active exploitation at the time of disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
