ZeroHour
Security Affairspublished ()ingested @securityaffairs

Multiple Endpoint Manager bugs patched by Ivanti, including remote auth bypass

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-10573
Stored Cross-Site Scripting in Ivanti Endpoint Manager Exposes Admin Sessions

CVE-2025-10573 is a stored cross-site scripting (CWE-79) flaw in Ivanti Endpoint Manager versions prior to 2024 SU4 SR1. A remote, unauthenticated attacker can plant malicious script content in the product, and when an administrator interacts with the affected view (user interaction is required), arbitrary JavaScript executes in the context of the administrator's browser session. An attacker who succeeds can act as an EPM administrator, potentially viewing or modifying administrative data, which the scope-changed CVSS 3.1 score of 6.1 reflects via low confidentiality and integrity impact. Organizations running Ivanti EPM on-premises, typically to manage large fleets of corporate endpoints, are affected. As of now there is no known public proof-of-concept and the flaw is not in CISA KEV, but EPSS assigns a 33.5% probability of exploitation within 30 days (98th percentile), indicating elevated risk.

Do: Upgrade Ivanti Endpoint Manager to 2024 SU4 SR1 or later as soon as possible, and apply the latest Ivanti patch rollups, since related advisories indicate Ivanti shipped fixes for multiple EPM issues in the same cycle. Until patched, restrict network access to the EPM core server and administrative console, and have administrators avoid engaging with unexpected or untrusted content in the console. After patching, review EPM administrator accounts and recent session activity for signs of unauthorized administrative actions.

6.133%
  • Ivanti Endpoint Manager prior to 2024 SU4 SR1
largetens of thousands of EPM core deployments worldwide (widely deployed enterprise endpoint-management platform)
CVE-2026-1602
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

NVD description · AI analysis pending
6.5<1%
  • ivanti endpoint manager
CVE-2026-1603
Authentication Bypass in Ivanti Endpoint Manager Leaks Stored Credentials

CVE-2026-1603 is an authentication bypass (CWE-288/CWE-306) in Ivanti Endpoint Manager (EPM) that affects versions before 2024 SU5. A remote, unauthenticated attacker can send crafted network requests to a vulnerable EPM core server without valid credentials. Successful exploitation grants read access to specific stored credential data held by EPM, which could be leveraged for further access within the environment. Any organization running an EPM deployment on a version earlier than 2024 SU5 is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09, confirming active exploitation in the wild, and its EPSS score of 80.6% (100th percentile) indicates a very high likelihood of exploitation in the next 30 days; no public proof-of-concept is known, suggesting private exploit use.

Do: Upgrade EPM core servers to version 2024 SU5 (or later) as soon as possible, in line with CISA's KEV and BOD 22-01 timelines, which have been shortened for this flaw. Until patched, restrict internet-facing exposure of EPM services and review EPM servers for anomalous authentication activity or signs of stored-credential access. If mitigations are unavailable, follow CISA's guidance to apply vendor-recommended mitigations or discontinue use of the affected product.

7.581% KEV
  • Ivanti Endpoint Manager (EPM) all versions before 2024 SU5
largetens of thousands of EPM core-server deployments (order of 10,000–100,000 installations), an estimate
Full article313 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 12, 2026

Ivanti patched over a dozen Endpoint Manager flaws, including a high-severity auth bypass that let attackers steal credentials remotely.

Ivanti released patches for more than a dozen vulnerabilities in Endpoint Manager, including flaws disclosed in October 2025. The update addresses a high-severity authentication bypass, tracked as CVE-2026-1603 (CVSS score of 8.6), that attackers could exploit remotely without credentials to access and steal sensitive login information.

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data. 

“An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.” reads the advisory.

The company also fixed a medium-severity SQL injection, tracked as CVE-2026-1602 (CVSS score of 6.5), in Ivanti Endpoint Manager.

“SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.” continues the advisory.

Trend Micro’s ZDI reported the flaws to Ivanti in November 2024, threat actors could exploit the bugs to escalate privileges and run code remotely.

The company said it is not aware of attacks in the wild exploiting these vulnerabilities before public disclosure.

EPM 2024 SU5 addressed both vulnerabilities.

In December, the software firm addressed a newly disclosed vulnerability, tracked as CVE-2025-10573 (CVSS score 9.6), in its Endpoint Manager (EPM) solution.

The vulnerability is a Stored XSS that could allow a remote unauthenticated attacker to execute arbitrary

“Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.” reads the advisory.

The flaw impacts Ivanti Endpoint Manager prior to version 2024 SU4 SR1.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Endpoint Manager)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/187882/uncategorized/multiple-endpoint-manager-bugs-patched-by-ivanti-including-remote-auth-bypass.html