🔴 CVE-2026-1603

CVE-2026-1603 is an authentication bypass vulnerability in Ivanti Endpoint Manager that allows remote unauthenticated attackers to leak stored credential data. This vulnerability is actively exploited according to CISA KEV listing and can be directly exploited against internet-facing EPM instances.

← Back to Overview
HIGH_RISK
Risk Level
8.6
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2026-02-10

Added to CISA KEV: 2026-03-09 27 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-03-09)

CVE-2026-1603 is an authentication bypass vulnerability affecting Ivanti Endpoint Manager (EPM) prior to version 2024 SU5 [3][4].

Here's a breakdown of what is known about its exploitation:

  • Internet-facing applications or services: The vulnerability can affect internet-facing instances of Ivanti EPM [1].
  • Evidence of active exploitation in the wild: There is no direct evidence in the provided search results indicating active exploitation in the wild for CVE-2026-1603. However, other Ivanti vulnerabilities (CVE-2026-1281 and CVE-2026-1340) have been confirmed as actively exploited zero-days [2], and CVE-2025-64446 was actively exploited [7].
  • Attack vectors and exploitation methods: The vulnerability allows a remote, unauthenticated attacker to leak specific stored credential data [3][4]. This is achieved through an authentication bypass using an alternate path or channel [6]. Successful exploitation could lead to the retrieval of sensitive credential information and unauthorized actions within the EPM environment [1].
  • Targeted attacks: The provided information does not specify if CVE-2026-1603 has been used in targeted attacks.
  • CISA Known Exploited Vulnerabilities status: CVE-2026-1603 is listed on the CISA Known Exploited Vulnerabilities (KEV) Catalog [5]. This indicates that CISA has evidence of active exploitation.
  • Technical details about internet exploitability: The vulnerability allows a remote unauthenticated attacker to bypass authentication and access stored credential data [3][4]. This implies that if an Ivanti EPM instance is accessible from the internet, an attacker could potentially exploit this vulnerability without prior authentication. Horizon3.ai offers a Rapid Response test to assess both internet-facing and internal EPM instances for exposure [1].
The recommended mitigation is to update Ivanti Endpoint Manager to version 2024 SU5 [1].

Sources

  1. Ivanti Endpoint Manager (EPM) | CVE-2026-1603 | Horizon3.ai

    CVE-2026-1603 is an authentication bypass vulnerability affecting Ivanti Endpoint Manager (EPM) prior to version 2024 SU5. The vulnerability allows a remote attacker to access stored credential data without proper authentication. Ivanti assigns a CVSS v3 score of 8.6, while NVD lists a score of 7.5.

  2. Ivanti EPMM RCE Zero-Days (CVE-2026-1281, 1340) | Horizon3.ai

    CVE-2026-1281 and CVE-2026-1340 are actively exploited RCE flaws in Ivanti EPMM. Verify exposure and confirm remediation with NodeZero Rapid Response.CVE-2026-1281 and CVE-2026-1340 are critical code injection vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM). The vulnerabilities allow…

  3. CVE-2026-1603 | ZEN SecDB Portal

    CVE-2026-1603 : An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific store...The Common Attack Pattern Enumeration and Classification (CAPEC™) effort provides a publicly available catalog of common attack patterns that…

  4. CVE-2026-1603 Detail - NVD

    CVE-2026-1603 Detail. Description. An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.Reference Type. ivanti: https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024?la…

  5. Known Exploited Vulnerabilities Catalog - CISA

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of vulnerabilities that have been exploited in the wild. Organizations should use the KEV catal…