Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ivanti Releases Crucial Patches for Endpoint Manager

Ivanti Releases Crucial Patches for Endpoint Manager

Posted on February 11, 2026 By CWS

Ivanti has released important security patches for its Endpoint Manager (EPM) software, addressing several vulnerabilities that were brought to light in October 2025. The update includes fixes for both high and medium severity issues that could be exploited remotely.

Key Vulnerabilities Addressed

Among the vulnerabilities, a significant one identified as CVE-2026-1603, is a high-severity authentication bypass flaw. This weakness could potentially expose credential data to unauthorized parties. Another medium-severity issue, tracked as CVE-2026-1602, involves an SQL injection defect. This particular vulnerability could allow attackers with authentication to access arbitrary data within the database.

The resolution of these vulnerabilities comes with the release of EPM 2024 SU5, which also addresses 11 other medium-severity issues disclosed in October. These problems, initially reported to Ivanti in November 2024, were highlighted by Trend Micro’s Zero Day Initiative, although they were not zero-day vulnerabilities in the technical sense.

Security Updates and Recommendations

Ivanti’s efforts to fix these security flaws include previous patches released in November 2025 for two high-severity vulnerabilities. The latest update completes the remediation of all outstanding issues. Importantly, Ivanti has stated that there are no known instances of these vulnerabilities being exploited in the wild. Nonetheless, users are strongly encouraged to upgrade to EPM 2024 SU5 without delay to ensure their systems remain protected.

Additionally, Ivanti has reminded users that EPM version 2022 is no longer supported, having reached its End of Life (EOL). Consequently, users should migrate to a supported version to continue receiving security updates.

Additional Advisory Updates

On the same day, Ivanti updated its advisory regarding two Endpoint Manager Mobile (EPMM) vulnerabilities, which have been exploited as zero-days. These vulnerabilities are tracked as CVE-2026-1281 and CVE-2026-1340 and have a CVSS score of 9.8, indicating their critical nature. They have been used for unauthenticated remote code execution, allowing attackers to deploy web shells and reverse shells for persistence.

Ivanti’s advisory now includes indicators of compromise (IoCs) and a detection script to assist users in identifying potential breaches. The company has also provided guidance to manage false positives in detection.

Staying informed about security updates such as these is crucial in maintaining robust cybersecurity defenses. Users are urged to apply the latest patches promptly and to remain vigilant against potential threats.

Security Week News Tags:authentication bypass, CVE-2026-1602, CVE-2026-1603, Cybersecurity, Endpoint Manager, EPM 2024 SU5, Ivanti, security patches, software updates, SQL injection, Vulnerabilities, zero-day

Post navigation

Previous Post: Cybercriminals Exploit AI to Distribute macOS Malware
Next Post: New Ransomware Threats BQTLock and GREENBLOOD Emerge

Related Posts

Nevada Confirms Ransomware Attack Behind Statewide Service Disruptions Nevada Confirms Ransomware Attack Behind Statewide Service Disruptions Security Week News
US Charges Cambodian Executive in Massive Crypto Scam and Seizes More Than  Billion in Bitcoin US Charges Cambodian Executive in Massive Crypto Scam and Seizes More Than $14 Billion in Bitcoin Security Week News
SonicWall Patches Critical SMA 100 Vulnerability, Warns of Recent Malware Attack SonicWall Patches Critical SMA 100 Vulnerability, Warns of Recent Malware Attack Security Week News
Chrome Sandbox Escape Earns Researcher 0,000 Chrome Sandbox Escape Earns Researcher $250,000 Security Week News
Runlayer Emerges From Stealth Mode With  Million in Funding Runlayer Emerges From Stealth Mode With $11 Million in Funding Security Week News
Connex Credit Union Data Breach Impacts 172,000 People Connex Credit Union Data Breach Impacts 172,000 People Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages
  • DragonForce Ransomware Group’s Expanding Cartel Operations
  • North Korean Hackers Exploit AI for Enhanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages
  • DragonForce Ransomware Group’s Expanding Cartel Operations
  • North Korean Hackers Exploit AI for Enhanced Cyber Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News