CVE-2026-1603: Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2026-03-09. EPSS: 88.3% chance of exploitation in the next 30 days.
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
Affected products
- Ivanti Endpoint Manager: before 2024 (fixed in 2024); version 2024 only
Published 2026-02-10. Last modified 2026-06-17.