Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Hackers Actively Exploiting Critical NGIN NGINX Vulnerability
May 18, 2026
Critical n8n Flaws Expose Automation Nodes to Vulnerabilities Full
May 18, 2026
Linus Torvalds Says AI Bug Reports Have Made Linux Security
May 18, 2026
Home/CyberSecurity News/Ivanti Endpoint Manager Flaw: Remote Arbitrary Data Leak
CyberSecurity News

Ivanti Endpoint Manager Flaw: Remote Arbitrary Data Leak

Ivanti has released critical security updates for its Endpoint Manager (EPM) platform, addressing two newly discovered vulnerabilities. These flaws could enable unauthorized access to sensitive...

Sarah simpson
Sarah simpson
February 10, 2026 2 Min Read
5 0

Ivanti has released critical security updates for its Endpoint Manager (EPM) platform, addressing two newly discovered vulnerabilities. These flaws could enable unauthorized access to sensitive database information and compromise user credentials.

The updates, released in version 2024 SU5, also resolve 11 medium-severity vulnerabilities previously disclosed in October 2025.

The security advisory highlights two primary vulnerabilities of significant concern. CVE-2026-1603, rated with a CVSS score of 8.6 (High), represents an authentication bypass flaw that allows remote unauthenticated attackers to leak specific stored credential data.

This vulnerability, classified under CWE-288, poses a substantial risk as it requires no user interaction and can be exploited over the network without authentication.

The second vulnerability, CVE-2026-1602, carries a CVSS score of 6.5 (Medium) and involves a SQL injection flaw. Remote authenticated attackers can exploit this weakness to read arbitrary data from the database, potentially exposing sensitive organizational information. The vulnerability affects data confidentiality but does not affect system integrity or availability.

CVE Number Description CVSS Score (Severity) Affected Versions Resolved Version
CVE-2026-1602 SQL injection allowing remote authenticated attacker to read arbitrary database data 6.5 (Medium) 2024 SU4 SR1 and prior 2024 SU5
CVE-2026-1603 Authentication bypass allowing remote unauthenticated attacker to leak stored credential data 8.6 (High) 2024 SU4 SR1 and prior 2024 SU5

Organizations running Ivanti Endpoint Manager version 2024 SU4 SR1 and earlier are vulnerable to these exploits. The vulnerabilities affect the core authentication and database query mechanisms, making them particularly concerning for enterprise environments managing multiple endpoints.

Ivanti has made the patched version, EPM 2024 SU5, available through its Ivanti License System (ILS). Administrators are strongly encouraged to apply the update immediately to mitigate potential risks.

The company has confirmed that no active exploitation was observed prior to public disclosure, as both vulnerabilities were reported through Ivanti’s responsible disclosure program.

The vulnerabilities were discovered by security researcher 06fe5fd2bc53027c4a3b7e395af0b850e7b8a044, working in collaboration with Trend Zero Day Initiative.

Ivanti has publicly acknowledged the researcher’s contribution to identifying these security gaps and emphasized its commitment to working with the security community to maintain product integrity.

These vulnerabilities underscore the ongoing challenges in enterprise software security, particularly in endpoint management solutions that handle privileged access and sensitive organizational data.

The authentication bypass vulnerability is especially concerning as it requires no prior authentication, potentially allowing attackers to gain initial access to credential stores.

Currently, there are no known indicators of compromise associated with these vulnerabilities, and Ivanti reports no evidence of exploitation in the wild. However, the public disclosure of technical details increases the urgency for organizations to deploy the available patches.

Organizations using Ivanti Endpoint Manager should prioritize updating to version 2024 SU5 and conduct security audits to ensure no unauthorized access occurred prior to patching. Ivanti continues to encourage security researchers to report vulnerabilities through its official disclosure channels.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

FortiOS Vulnerability Allows LDAP Authentication Bypass

Next Post

FortiSandbox XSS Flaw Allows Arbitrary Command Vulnerability Attackers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Avada Builder Flaws Affect 1 Million WordPress Sites with
May 18, 2026
Microsoft Confirms Windows 11 Update Fails With Error 0x800f0922
May 18, 2026
Critical Windows ‘MiniPlasma’ Zero-Day Grants SYSTEM Access
May 18, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Jennifer sherman
Jennifer sherman
Sarah simpson
Sarah simpson
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us