Ivanti released a security update for Ivanti Desktop and Server Management (DSM) to address CVE-2026-3483, a high-severity local privilege escalation flaw affecting DSM versions up to and including 2026.1. The issue is described as an exposed dangerous method (CWE-749) that could allow a local authenticated attacker to elevate privileges with low attack complexity and no user interaction once they already have access to a target system.
Ivanti states it has no evidence of exploitation in the wild at the time of disclosure and that the vulnerability does not impact other Ivanti solutions. The fix is available in DSM 2026.1.1 (distributed via the Ivanti License System), and organizations running affected versions are advised to prioritize upgrading and follow Ivanti’s security advisory remediation guidance.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-10, the Canadian Centre for Cyber Security published advisory AV26-214 referencing Ivanti's disclosure of CVE-2026-3483. It encouraged organizations to review Ivanti's guidance and apply the necessary updates to remediate the issue.
Ivanti said the vulnerability was fixed in DSM version 2026.1.1 and made the update available through the Ivanti License System. The company urged customers running DSM 2026.1 or earlier to update promptly and stated it was not aware of active exploitation or public IOCs at disclosure time.
On 2026-03-10, Ivanti published a security advisory for a high-severity local privilege escalation vulnerability, CVE-2026-3483, affecting Ivanti Desktop and Server Management (DSM) 2026.1 and earlier. The flaw was described as an exposed dangerous method that an authenticated local user could abuse to gain elevated privileges.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
3 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecybersecuritynews.com
Open sourceivanti.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.