
[CIVN-2026-0130] Multiple vulnerabilities in Ivanti Endpoint Manager
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple vulnerabilities in Ivanti Endpoint Manager
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Ivanti Endpoint Manager 2024 SU4 SR1 and prior versions.
Overview
Multiple vulnerabilities have been reported in Ivanti Endpoint Manager, which could allow an attacker to obtain sensitive information and bypass security restrictions on the target system.
Target Audience:
All end-user organizations and individuals using affected Ivanti Endpoint Manager.
Risk Assessment:
High risk of unauthorized access and disclosure of information stored in the application database.
Impact Assessment:
Potential unauthorized access to sensitive information and compromise of system security.
Description
Ivanti Endpoint Manager (EPM) is a Unified Endpoint Management (UEM) solution that enables centralized management and security of enterprise devices across Windows, macOS, Linux, iOS, and Android environments.
Multiple vulnerabilities have been reported in Ivanti Endpoint Manager due to improper input validation in the affected software.
Successful exploitation of these vulnerabilities could allow an attacker to obtain sensitive information and bypass security restrictions on the target system.
Solution
Apply appropriate updates as mentioned by the vendor
https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024?language=en_US
Vendor Information
Ivanti
https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024?language=en_US
References
Ivanti
https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024?language=en_US
CVE Name
CVE-2026-1602
CVE-2026-1603
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmmyztcACgkQ3jCgcSdc
ys8khg//Q9p0FXkEEYVlWuiuLaDrALQtlGcbwz33erkzj/IHBkko/7i3WrC7mKUy
I6SFoKHE5l42WBGhYfU8avQpZd1AWAHb5jOQ0ySEpkYw5v4uerISlg5wS8jt+LFx
dmbnKvSWjAE9+ydw0vckDzYsky7Zk1CTdC5uzCMcjd8dUVY6lE8F+vmscdXEc0h/
h4My3vAZL4Hylvp4OVqmB1UoudsGcHL2uY9Xe/vNvP0/dvDNoXjoxdBB+VwDszd9
HHU+XqEk+hE3LppORvKWttNprV3JnzIhBkt1Ba3JA583tsYjw/L4AkP3MoS56qYs
vZg+zQn4Dva6dsXupxnid5AxZqfO9LaE2IfiyQ1iSnnTFx0U2UE7np8Pw2ZZGnnt
1Go4HnXcXDpHYYfondTPykX+FyzG9n1bbpq3gTZyKi8NOK4prFbuWJEqhnzDJkLD
myHtZkIpMskXXXeRSSj9K930ss5474NQB4+TXclEdRoTSXnJSZIZa+Mfzmq6ok/W
1u7Jerkt70JkMg/lCJYem8FjzB1Xp2ogCz6/HQ8v8rUjnIZzFtIjFRMa6vPq5Vja
yQXsvWZpOif7wA7vHG9LgQIzYvIn5Muu36FwIhm0+ZjwE8yVeuLDFukpOfgowt2w
uQc1Avv7+VYz+4xtT8QPfvZ9hPWJQjZm01ZmzbFsyIrllXMqK5c=
=YUL1
—–END PGP SIGNATURE—–


