Ivanti has announced the release of security updates for its Endpoint Manager (EPM) , fixing over a dozen vulnerabilities that could be exploited by attackers, even remotely. The fixes include issues that were previously disclosed as far back as October 2025, confirming that the platform remains under the microscope of researchers and cybercriminals alike.

In a new alert, the company specifically warns about two bugs — one high and one medium severity — that could open the way to data exposure and access to critical systems.
CVE-2026-1603: Authentication Bypass and Credential Leakage
The most serious of the new vulnerabilities is listed as CVE-2026-1603 and is classified as a high-severity bug. It is an authentication bypassthat could lead to credential data exposure.
Simply put, an attacker could gain access to sensitive information without having the necessary privileges, which is a critical risk in enterprise endpoint management environments, where credentials can be used to further infiltrate the network.
See also: CISA: 6 new Microsoft vulnerabilities in the KEV Catalog
CVE-2026-1602: SQL Injection and Database Access
The second vulnerability, of medium severity, is tracked as CVE-2026-1602 and concerns a classic but always dangerous SQL injection scenario.
In this case, an already authenticated user could execute malicious queries, gaining the ability to read arbitrary data from the system database.
Although initial access is required, such vulnerabilities often act as a “second step” in attacks, helping attackers expand their privileges and collect critical information.

Endpoint Manager 2024 SU5: Need for immediate update
Both issues have been fixed in the EPM 2024 SU5, which also includes patches for 11 other medium-severity vulnerabilitiesthat Ivanti had flagged since October.
The issues were initially reported to the company in November 2024 and later publicized by Zero Day Initiative (ZDI) as "0days," although technically they were not true zero-days (since they had already been disclosed to the manufacturer).
Successful exploitation of some of the flaws could allow:
- privilege escalation
- remote code execution
- full control of endpoints
Ivanti had fixed two of the most serious vulnerabilities in November 2025 and has now completed the patching process for the rest.
See also: Hackers exploit SolarWinds WHD vulnerabilities
No known attacks — but the risk remains
The company says there is currently no evidence of active exploitation of these vulnerabilities. However, experience shows that such vulnerabilities are often exploited quickly after they are disclosed, especially in endpoint management products that are high-value targets.
For this reason, users are urged to upgrade immediately to version 2024 SU5.
End of support for EPM 2022: Time to transition
Another important point of the announcement is that the EPM 2022 version has now reached the end of its lifecycle (End of Life – EOL) and no longer receives security updates.
This means that organizations that continue to use it remain exposed to new threats without protection. Ivanti urges its customers to migrate to supported versions as soon as possible.

Zero-days also in Endpoint Manager Mobile (EPMM)
At the same time, Ivanti has also updated its guidance for two recently disclosed zero-day vulnerabilities in Endpoint Manager Mobile (EPMM): CVE-2026-1281 and CVE-2026-1340 (CVSS 9.8).
See also: Six new vulnerabilities discovered in the n8n automation platform
The vulnerabilities lead to unauthorized remote code execution (RCE) and have already been exploited to install web shells and reverse shells, with the aim of maintaining access to systems.
Ivanti has now added:
- indicators of compromise (IoCs)
- detection scenarios
- instructions for avoiding false positive results
Endpoint tools at the center of attacks
Ivanti's new patch series confirms that endpoint management tools are now critical targets for cybercriminals. A vulnerability in such platforms can give access to an entire corporate network.
Promptly installing updates and moving to supported versions is not just good practice — it's a necessary defense against modern threats.
