
🚨 CVE-2026-1602: Vulnerability Alert Critical Unauthenticated RCE via Malformed OTA Update Package! An attacker sends a specially crafted, digitally signed Over-The-Air (OTA) update package to the Ivanti EPM server—bypassing signature validation due to insecure certificate chain parsing and ASN.1 decoding flaws—resulting in arbitrary code execution with SYSTEM privileges. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-1602 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-1602" Search Dork: app="Ivanti EPM" Exposure: 77 instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJJdmFudGkgRVBNIg==&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260212 #CVE #RCE #Ivanti #SupplyChain #ZeroDay #DarkEye #ZoomEye
Post summary
An alert describing a critical unauthenticated remote code execution flaw in Ivanti EPM’s OTA update processing, with technical details but no proof‑of‑concept, exploit code, or active exploitation evidence.






