CVE-2026-1603: Remote Unauthenticated Attacker Can Steal Ivanti EPM Secrets
ID: ec9b9ec0-1fe1-5a0d-9ecf-02822d861037
STIX ID: report--ec9b9ec0-1fe1-5a0d-9ecf-02822d861037
Feed Name: securityonline.info
Threat Score
Ivanti published an advisory fixing two vulnerabilities in Endpoint Manager—CVE-2026-1603 (authentication bypass, CVSS 8.6) that can leak stored credentials and enable further compromise, and CVE-2026-1602 (SQL injection, CVSS 6.5) that allows authenticated attackers to read arbitrary database data; administrators are urged to upgrade to 2024 SU5 immediately, and Ivanti reports no known active exploitation at disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
