Ivanti has released a security update to fix multiple vulnerabilities across Ivanti Endpoint Manager (EPM).

The addressed vulnerabilities could allow the remote attacker to read arbitrary data from the database, leak stored credential data, and bypass security restrictions on the affected systems.

Sample of the addressed vulnerabilities:

Ivanti Endpoint Manager Authentication Bypass Vulnerability (CVE-2026-1603):

  • CVSS: 8.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Bypass Security
Vulnerabilities
  • CVE-2026-1603
  • CVE-2026-1602
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References