CVE-2026-1602Patch(ivanti / endpoint_manager)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch ivanti endpoint_manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-02-12); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Vendors
Products
endpoint_manager

1 version affected across 1 product

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-02-10: 1Mentions · 2026-02-11: 2Mentions · 2026-02-12: 3Mentions · 2026-02-13: 1Mentions · 2026-02-18: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-11: 2Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-18: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-11: 2Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 1Technical Details · 2026-02-18: 102-1002-1102-1202-1302-1803-11
Signal classification3 categories
Patch
555.6%
Disclosure
333.3%
General
111.1%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-02-101
Patch1
2026-02-112
Patch2
2026-02-123
Disclosure2Patch1
2026-02-131
Disclosure1
2026-02-181
Patch1
2026-03-111
General1
Full discourse9 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-1602: Vulnerability Alert Critical Unauthenticated RCE via Malformed OTA Update Package! An attacker sends a specially crafted, digitally signed Over-The-Air (OTA) update package to the Ivanti EPM server—bypassing signature validation due to insecure certificate chain parsing and ASN.1 decoding flaws—resulting in arbitrary code execution with SYSTEM privileges. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-1602 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-1602" Search Dork: app="Ivanti EPM" Exposure: 77 instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJJdmFudGkgRVBNIg==&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260212 #CVE #RCE #Ivanti #SupplyChain #ZeroDay #DarkEye #ZoomEye

    Post summary

    An alert describing a critical unauthenticated remote code execution flaw in Ivanti EPM’s OTA update processing, with technical details but no proof‑of‑concept, exploit code, or active exploitation evidence.

    0902483.0K
    11.9K followersView on X
  • DarkEye@darkeye_team
    Disclosure

    🚨 Detailed Analysis for CVE-2026-1602 (Vulnerability Alert) Stop guessing the risk. The technical details are ready. 🔥 $5 Special Trial to celebrate our CVE Feed launch! Get the Analysis & Prioritized Asset List now: 🔗 https://www.darkeye.org/vuln/cve/CVE-2026-1602 Critical Unauthenticated Remote Code Execution! Exploits an unauthenticated deserialization flaw in Ivanti EPM's web console to execute arbitrary code as SYSTEM. cc: @zoomeye_team (77 targets detected 🎯 (Early Warning)) #CVE20261602 #CVE #Ivanti #RCE #DarkEye #ZoomEye #BugBounty

    Post summary

    The text presents a detailed disclosure of CVE-2026-1602, describing an unauthenticated deserialization flaw in Ivanti EPM that permits remote code execution as SYSTEM, but it provides no PoC, exploit, patch, or evidence of active exploitation.

    01011197
    956 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Ivanti released update for its #Endpoint Manager (EPM) to address #CVE-2026-1603, a high-severity #authentication bypass that allows a remote unauthenticated attacker to access stored credential data, and # CVE-2026-1602, an #SQL injection flaw. https://ccb.belgium.be/advisories/warning-security-update-ivanti-endpoint-manager-vulnerabilities-patch-immediately

    Post summary

    Ivanti released an update to fix two high‑severity vulnerabilities—an authentication bypass (CVE‑2026‑1603) and an SQL injection flaw (CVE‑2026‑1602)—and urges users to apply the patch immediately.

    02010297
    7.2K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-3094 2 - CVE-2025-43300 3 - CVE-2026-2796 4 - CVE-2026-1602 5 - CVE-2025-11411 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post enumerates trending CVE IDs but offers no further context or actionable information.

    00020223
    1.7K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Ivanti Endpoint Manager Patch Fixes Auth Bypass + SQLi That Expose Stored Credentials Ivanti patched two Endpoint Manager (EPM) flaws—CVE-2026-1603 (auth bypass, CVSS 8.6) that can leak stored credential data without login and CVE-2026-1602 (SQLi, CVSS 6.5) that lets authenticated attackers read arbitrary database data—fixed in EPM 2024 SU5. This matters because EPM holds privileged endpoint/admin data, so credential leakage or DB reads can accelerate lateral movement and full environment compromise if instances are reachable. 🎯 Target: Global/Enterprise (Endpoint Management) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/multiple-ivanti-endpoint-manager-vulnerability/

    Post summary

    Ivanti has released patches for CVE‑2026‑1603 (auth bypass, CVSS 8.6) and CVE‑2026‑1602 (SQLi, CVSS 6.5) to mitigate credential leakage risks in its Endpoint Manager product.

    00002103
    191 followersView on X
  • iototsecnews@iototsecnews
    Patch

    Ivanti EPM の脆弱性 CVE-2026-1602/1603 が FIX:リモート攻撃による機密データの漏洩 https://iototsecnews.jp/2026/02/10/ivanti-endpoint-manager-vulnerability-lets-remote-attacker-leak-arbitrary-data/ 企業内の PC やサーバを一括管理する Ivanti Endpoint Manager で、機密情報の漏洩につながる深刻な脆弱性が発見されました。この問題の原因は、システムの中核である “認証の仕組み” と “データベースへの命令処理” に、設計上の不備があったことです。具体的には、外部から送られる特殊な通信に対して、本来は必要となる本人確認を飛び越えてしまう不具合や、データベースへの命令文を不正に書き換えられてしまう不備が存在しました。脆弱性の観点では、CVE-2026-1603 (認証バイパス) と CVE-2026-1602 (SQL インジェクション) が特定されています。ご利用のチームは、ご注意ください。 #CVE20261602 #CVE20261603 #EndpointManager #Ivanti #Vulnerability

    Post summary

    Ivanti Endpoint Manager has two critical vulnerabilities—an authentication bypass (CVE‑2026‑1603) and an SQL injection (CVE‑2026‑1602)—that allow remote attackers to leak arbitrary data; a patch has been issued.

    01000181
    484 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.』😨 CVE-2026-1602 CVE-2026-1603 Security Advisory EPM February 2026 for EPM 2024 https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024?language=en_US

    Post summary

    The text discloses an authentication bypass in Ivanti Endpoint Manager that permits credential leakage, and references a vendor advisory that presumably contains a patch or mitigation.

    00000479
    6.7K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Ivanti Patches 12+ Endpoint Manager Flaws, Including Pre-Auth Credential Leak (CVE-2026-1603) Ivanti fixed multiple Endpoint Manager issues, led by CVE-2026-1603 (CVSS 8.6) that lets a remote unauthenticated attacker bypass auth and leak specific stored credential data, plus CVE-2026-1602 (SQLi) and earlier stored XSS fixes. This matters because EPM is high-privilege infrastructure—credential exposure and DB read paths can rapidly turn into domain-wide compromise if not patched (2024 SU5). 🎯 Target: Global / Enterprises using Ivanti Endpoint Manager #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://securityaffairs.com/187882/uncategorized/multiple-endpoint-manager-bugs-patched-by-ivanti-including-remote-auth-bypass.html

    Post summary

    Ivanti has released patches for multiple Endpoint Manager vulnerabilities, notably CVE-2026-1603 which enables unauthenticated credential leakage. The advisory urges immediate update to prevent potential domain-wide compromise.

    00000109
    191 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Ivanti Patches Endpoint Manager Auth Bypass Exposing Credentials + SQLi Read Flaw Ivanti released EPM 2024 SU5 fixing CVE-2026-1603 (auth bypass exposing credential data) and CVE-2026-1602 (authenticated SQLi allowing arbitrary DB reads), plus 11 additional medium-severity issues disclosed in Oct 2025. Ivanti says it has no evidence of in-the-wild exploitation, but urges upgrades—especially since EPM 2022 is EOL and unpatched. 🎯 Target: Global/Enterprise (Ivanti Endpoint Manager) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/ivanti-patches-endpoint-manager-vulnerabilities-disclosed-in-october-2025/

    Post summary

    Ivanti issued patch EPM 2024 SU5 to mitigate CVE‑2026‑1603 (auth bypass) and CVE‑2026‑1602 (authenticated SQLi), confirms no wild exploitation and urges upgrades.

    00000112
    191 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager---
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--

Explore more