CISA Warns About Ivanti EPM Vulnerability Exploited in Attacks (CVE-2026-1603)

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) informs users that the Ivanti Endpoint Manager vulnerability is being exploited in the wild. CISA added the vulnerability to its Known Exploited Vulnerabilities Catalog, urging users to patch before March 23, 2026.

Ivanti September Security Updates Address Multiple Vulnerabilities in Popular Products

Ivanti released its security bulletin for September, addressing 13 vulnerabilities. The vulnerabilities impact Ivanti Endpoint Manager, Ivanti Connect Secure, Policy Secure, ZTA Gateways, and Neurons for Secure Access. As per the Ivanti advisory, no proof exists for any of the vulnerabilities being exploited in the wild.

Ivanti Patches Critical SQL Injection Vulnerability in Endpoint Manager (CVE-2023-39336)

 A critical severity SQL injection vulnerability has been discovered in the Ivanti Endpoint Manager. Tracked as CVE-2023-39336, the vulnerability has been given a critical severity rating with a CVSS score of 9.6. Successful exploitation of the vulnerability may allow an attacker to execute arbitrary SQL queries and retrieve output without needing authentication.