logo

CVE-2026-1603: Remote Unauthenticated Attacker Can Steal Ivanti EPM Secrets

ID: ec9b9ec0-1fe1-5a0d-9ecf-02822d861037

STIX ID: report--ec9b9ec0-1fe1-5a0d-9ecf-02822d861037

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-02-12

Date Updated: 2026-04-23

Author: Ddos

...
...

Ivanti published an advisory fixing two vulnerabilities in Endpoint Manager—CVE-2026-1603 (authentication bypass, CVSS 8.6) that can leak stored credentials and enable further compromise, and CVE-2026-1602 (SQL injection, CVSS 6.5) that allows authenticated attackers to read arbitrary database data; administrators are urged to upgrade to 2024 SU5 immediately, and Ivanti reports no known active exploitation at disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.