Ivanti Security Update – 11 March 2026

Ivanti has released a security update to fix a vulnerability across Ivanti Desktop and Server Management (DSM) versions 2026.1 and prior.

The addressed vulnerability could allow the local authenticated attacker to gain elevated privileges on the affected product.

Ivanti Desktop and Server Management Privilege Escalation Vulnerability (CVE- 2026-3483):

  • CVSS: 7.8
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Gain Privileges

It should be highlighted that Ivanti is aware that the Ivanti Endpoint Manager (EPM) vulnerability “CVE-2026-1603” that was patched one month ago is being exploited in the wild.

Vulnerabilities

CVE-2026-3483

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References