Home Ivanti CVE-2026-1603
CRITICAL: THIS VULNERABILITY IS ACTIVELY BEING EXPLOITED IN THE WILD (CISA KEV CATALOG)
Back to Ivanti

CVE-2026-1603

Exploited

Ivanti Endpoint Manager - Core

Ivanti CVSS 8.6 Updated March 16, 2026

Executive Risk Summary

"An authentication bypass vulnerability in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data, posing a significant risk to the security of the affected systems. This vulnerability can be exploited to gain unauthorized access to sensitive information, emphasizing the need for immediate patching or mitigation."

Operational Audit Arsenal

Target Type Software
Target Asset Ivanti Endpoint Manager
Standard Path Program Files/Ivanti/Management Console

Manual Verification Required

This is a non-Windows asset (Ivanti). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Moderate, potential service interruption during update

Internal Work Notes

CVE-2026-1603: Ivanti Endpoint Manager authentication bypass vulnerability - apply EPM-2024 SU5 or later to mitigate

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Ivanti Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.