Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Ivanti Patches Endpoint Manager Vulnerabilities Disclosed in October 2025

It also fixed a high-severity authentication bypass that could be exploited remotely without authentication to obtain credentials.

Ivanti vulnerability exploited

Ivanti on Tuesday announced patches for over a dozen vulnerabilities in Endpoint Manager (EPM), including issues that were first disclosed in October 2025.

In a new advisory, the company warns of a high-severity bug and a medium-severity flaw resolved in EPM, both of which could be exploited remotely.

Tracked as CVE-2026-1603, the high-severity weakness is described as an authentication bypass leading to the exposure of credential data.

The medium-severity flaw, tracked as CVE-2026-1602, is an SQL injection security defect that could allow authenticated attackers to read arbitrary data from the database.

Both issues were resolved in EPM 2024 SU5, which also includes fixes for 11 medium-severity vulnerabilities that Ivanti warned about in October.

The issues were reported to Ivanti in November 2024 and were publicly disclosed by Trend Micro’s Zero Day Initiative (ZDI) as ‘0day’, although they were not technically zero-days. Successful exploitation of these bugs could allow attackers to escalate their privileges and execute arbitrary code remotely.

Advertisement. Scroll to continue reading.

In November 2025, Ivanti rolled out fixes for two of the bugs, both high-severity weaknesses, and has now released patches for the remaining flaws.

The company says it is not aware of any of these vulnerabilities being exploited in the wild, but users are advised to update to EPM 2024 SU5 as soon as possible.

As Ivanti warned in October, EPM version 2022 has reached End of Life (EOL) and is no longer receiving security updates. Users should migrate to a supported EPM version.

On Tuesday, Ivanti also updated its advisory for two recently disclosed Endpoint Manager Mobile (EPMM) vulnerabilities that have been exploited as zero-days.

Tracked as CVE-2026-1281 and CVE-2026-1340 (CVSS score of 9.8) and leading to unauthenticated remote code execution (RCE), they were exploited to deploy web shells and reverse shells for persistence, Ivanti said in late January.

Last week, the company updated its advisory to include indicators of compromise (IoCs) and a detection script, and has now included guidance on false positives.

Related: Fortinet Patches High-Severity Vulnerabilities

Related: 6 Actively Exploited Zero-Days Patched by Microsoft With February 2026 Updates

Related: SAP Patches Critical CRM, S/4HANA, NetWeaver Vulnerabilities

Related: Ivanti EPM Update Patches Critical Remote Code Execution Flaw

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

1Kosmos has named Frank Cohen Chief Revenue Officer.

ServiceNow has appointed Simon Mouyal as Chief Marketing Officer.

James Wilkinson has been named Chief Information Security Officer for the City of Dallas.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.