CVE Watchtower β Back to CVE ListCVE-2026-1602NVDDescriptionSQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.Severity LevelMEDIUM (6.5)Published Date10/02/2026Last Modified12/02/2026Exploitation Status????Referenceshttps://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024?language=en_US