CVE-2026-1603Active Exploitation(ivanti / endpoint_manager)

CRITICALCVSS 7.5 · HIGHCISA KEV

Exploitation observed; activity peaked at 16 mentions and remains active

Immediate actions

  • Patch ivanti endpoint_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-23. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-288CWE-306

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • endpoint_manager

Threat summary

  • Active exploitation appears in 48 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 85 mentions across 24 observed days

What's happening

  • Active exploitation reported across 48 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 33 signals
  • Technical details provided in 58 signals
  • Disclosure: 20 classified signals
  • Peaked 14d ago at 16 mentions (2026-03-10); latest day: 1
  • 85 total mentions across 24 days

Affected systems

Vendors
Products
endpoint_manager

1 version affected across 1 product

Deep dive

Activity timeline85 mentions / 24d
0481216Mentions · 2026-02-10: 3Mentions · 2026-02-11: 4Mentions · 2026-02-12: 3Mentions · 2026-02-13: 5Mentions · 2026-02-14: 2Mentions · 2026-02-16: 1Mentions · 2026-02-17: 2Mentions · 2026-02-18: 1Mentions · 2026-03-09: 6Mentions · 2026-03-10: 16Mentions · 2026-03-11: 9Mentions · 2026-03-12: 1Mentions · 2026-03-13: 3Mentions · 2026-03-14: 1Mentions · 2026-03-15: 6Mentions · 2026-03-16: 7Mentions · 2026-03-17: 3Mentions · 2026-03-18: 3Mentions · 2026-03-21: 1Mentions · 2026-03-23: 2Mentions · 2026-03-24: 1Mentions · 2026-04-03: 1Mentions · 2026-05-04: 3Mentions · 2026-05-21: 1PoC Mentioned / Linked · 2026-02-11: 1PoC Mentioned / Linked · 2026-02-13: 1PoC Mentioned / Linked · 2026-02-17: 1PoC Mentioned / Linked · 2026-05-04: 1Exploit Tool / Code · 2026-05-04: 1Active Exploitation · 2026-02-11: 1Active Exploitation · 2026-02-14: 1Active Exploitation · 2026-02-17: 1Active Exploitation · 2026-03-09: 2Active Exploitation · 2026-03-10: 15Active Exploitation · 2026-03-11: 8Active Exploitation · 2026-03-12: 1Active Exploitation · 2026-03-13: 2Active Exploitation · 2026-03-15: 4Active Exploitation · 2026-03-16: 4Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-03-18: 2Active Exploitation · 2026-03-23: 2Active Exploitation · 2026-03-24: 1Active Exploitation · 2026-04-03: 1Active Exploitation · 2026-05-04: 2Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-11: 4Patch / Workaround · 2026-02-12: 2Patch / Workaround · 2026-02-13: 2Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-03-10: 12Patch / Workaround · 2026-03-11: 5Patch / Workaround · 2026-03-13: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-16: 2Patch / Workaround · 2026-03-23: 1Patch / Workaround · 2026-05-21: 1Technical Details · 2026-02-10: 3Technical Details · 2026-02-11: 4Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 3Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 2Technical Details · 2026-02-18: 1Technical Details · 2026-03-09: 3Technical Details · 2026-03-10: 9Technical Details · 2026-03-11: 5Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 2Technical Details · 2026-03-14: 1Technical Details · 2026-03-15: 4Technical Details · 2026-03-16: 5Technical Details · 2026-03-17: 2Technical Details · 2026-03-18: 2Technical Details · 2026-03-21: 1Technical Details · 2026-03-23: 2Technical Details · 2026-03-24: 1Technical Details · 2026-04-03: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-21: 102-1002-1202-1402-1703-0903-1103-1303-1503-1703-2103-2405-0405-21
Signal classification6 categories
Active Exploitation
4654.1%
Disclosure
2023.5%
Patch
1214.1%
General
55.9%
PoC
11.2%
Exploit
11.2%
Referenced assets62 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-103
Disclosure2Patch1
2026-02-114
Active Exploitation1Patch3
2026-02-123
Disclosure1Patch2
2026-02-135
General2Patch2PoC1
2026-02-142
Active Exploitation1General1
2026-02-161
Disclosure1
2026-02-172
Active Exploitation1Disclosure1
2026-02-181
Disclosure1
2026-03-096
Active Exploitation2Disclosure3General1
2026-03-1016
Active Exploitation15Patch1
2026-03-119
Active Exploitation7Disclosure1Patch1
2026-03-121
Active Exploitation1
2026-03-133
Active Exploitation2Disclosure1
2026-03-141
Disclosure1
2026-03-156
Active Exploitation4Disclosure2
2026-03-167
Active Exploitation3Disclosure2General1Patch1
2026-03-173
Active Exploitation1Disclosure2
2026-03-183
Active Exploitation2Disclosure1
2026-03-211
Disclosure1
2026-03-232
Active Exploitation2
2026-03-241
Active Exploitation1
2026-04-031
Active Exploitation1
2026-05-043
Active Exploitation2Exploit1
2026-05-211
Patch1
Full discourse20 posts
  • watchTowr@watchtowrcyber
    General

    2026, the year of the AI-driven attacker that could do back flips, they said. Meanwhile, there's a magic number that allows Auth Bypass against Ivanti EPM (CVE-2026-1603) something about a pledge 🙄 https://t.co/kN6kPVLB41

    Post summary

    The tweet references an authentication bypass vulnerability (CVE-2026-1603) in Ivanti EPM, citing a magic number but offering no PoC, exploit code, patch, or evidence of active exploitation.

    664135713629.3K
    10.9K followersView on X
  • Defused@DefusedCyber
    Active Exploitation

    🚨 The Ivanti EPM vuln disclosed by @watchtowrcyber yesterday (CVE-2026-1603) is now being actively exploited 🍯Note that we don't run an EPM stream, but attackers are actively trying this against EPMM (a completely separate product) Track activity 👉 https://console.defusedcyber.com/intel https://t.co/j1ZMkN9pGK

    Post summary

    CVE-2026-1603, a vulnerability in Ivanti EPM, is being actively exploited in the wild; attackers target both EPM and the separate EPMM product, with activity tracked via defusedcyber's intel platform.

    111037166.0K
    6.0K followersView on X
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️ We added Omnissa Workspace ONE UEM vulnerability CVE-2021-22054, SolarWinds Web Help Desk vulnerability CVE-2025-26399, & Ivanti Endpoint Manager vulnerability CVE-2026-1603 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q for more information. #Cybersecurity #InfoSec https://t.co/fcNCCfmzdF

    Post summary

    The tweet announces that three CVEs—CVE-2021-22054, CVE-2025-26399, and CVE-2026-1603—have been added to the DHS KEV Catalog, indicating they are acknowledged as potentially exploitable, though no PoC, patch, or technical detail is provided.

    11204216.8K
    292.6K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/9追加) 🛡️No.1538 CVE-2021-22054 Omnissa Workspace ONE Server-Side Request Forgery ============= CVSSスコア: 7.5 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 種別:サーバサイドのリクエストフォージェリ (CWE-918 / CISA-ADP) 深刻度:重要 国内影響度判定(※):中 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートから細工されたリクエストを介して、機密情報にアクセスされる恐れがあります。(旧称:VMware Workspace One UEM) https://web.archive.org/web/20211222154335/https://www.vmware.com/security/advisories/VMSA-2021-0029.html 🛡️No.1539 CVE-2025-26399 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:信頼できないデータのデシリアライゼーション (CWE-502 / CISA-ADP) 深刻度:緊急🔥 国内影響度判定(※):高 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートからホスト マシン上でコマンドを実行される恐れがあります。 https://www.solarwinds.com/trust-center/security-advisories/cve-2025-26399 🛡️No.1540 CVE-2026-1603 Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability ============= CVSSスコア: 8.6 (Base) / ivanti CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N 種別:代替パスまたはチャネルを使用した認証回避 (CWE-288 / ivanti) 深刻度:重要 国内影響度判定(※):中~高 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、リモートから特定の保存された資格情報データを窃取される恐れがあります。 https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024 ※ ChatGPTによる判定結果。試験的に行っているもので、誤判定の可能性があります。 CISA Adds Three Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/03/09/cisa-adds-three-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirmed exploitation of three CVEs, added them to its catalog, and provided technical details along with vendor patch references.

    020623.8K
    42.7K followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    🚨 CISA KEV: Ivanti Endpoint Manager (EPM) authentication bypass (CVE-2026-1603) Unauthenticated attackers can leak stored credential data from your endpoint management system. If you're managing endpoints in a DIS environment, this is your crown jewels. Detection strategies and mitigation in thread 👇

    Post summary

    CISA has identified an authentication bypass in Ivanti Endpoint Manager (CVE-2026-1603) that is being actively exploited to leak credentials, and mitigation guidance is available.

    51110182
    330 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    🚨 CISA KEV: Ivanti Endpoint Manager (EPM) authentication bypass (CVE-2026-1603) Unauthenticated attackers can leak stored credential data from your endpoint management system. If you're managing endpoints in a DIS environment, this is your crown jewels. Detection strategies and mitigation in thread 👇

    Post summary

    CISA has flagged CVE-2026-1603 as a known exploited vulnerability, enabling unauthenticated attackers to retrieve stored credentials from Ivanti Endpoint Manager. Detection methods and mitigation strategies are available.

    50010145
    331 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    🚨 CISA KEV: Ivanti EPM RCE (CVE-2026-1603) Ivanti EPM (Endpoint Manager) Remote Code Execution vulnerability. This is a critical vulnerability in a widely used endpoint management platform. Thread on what you need to know 👇

    Post summary

    CISA has identified active exploitation of a critical RCE vulnerability in Ivanti Endpoint Manager (CVE-2026-1603); no PoC, exploit code, or patch details are provided.

    5000054
    331 followersView on X
  • Patrick Roland@DeusLogica
    Disclosure

    🚨 CISA KEV: Ivanti EPM RCE (CVE-2026-1603) Ivanti EPM (Endpoint Manager) Remote Code Execution vulnerability. This is a critical vulnerability in a widely used endpoint management platform. Thread on what you need to know 👇

    Post summary

    The announcement flags CVE-2026-1603 as a critical Remote Code Execution flaw in Ivanti EPM, identified as a CISA KEV, with no PoC, exploitable code, or patch information provided.

    5000072
    333 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    🚨 CISA KEV: Ivanti EPM RCE (CVE-2026-1603) Ivanti EPM (Endpoint Manager) Remote Code Execution vulnerability. This is a critical vulnerability in a widely used endpoint management platform. Thread on what you need to know 👇

    Post summary

    CISA has identified CVE‑2026‑1603 in Ivanti EPM as a critical Remote Code Execution flaw that is actively exploited in the wild.

    5000074
    331 followersView on X
  • Patrick Roland@DeusLogica
    Active Exploitation

    🚨 CISA KEV: Ivanti EPM RCE (CVE-2026-1603) Ivanti EPM (Endpoint Manager) Remote Code Execution vulnerability. This is a critical vulnerability in a widely used endpoint management platform. Thread on what you need to know 👇

    Post summary

    The text announces a CISA-known-exploited CVE‑2026‑1603 affecting Ivanti Endpoint Manager, emphasizing its critical remote code execution risk, yet it lacks PoC, exploit code, or mitigation details.

    5000071
    331 followersView on X
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-080|CVE-2026-1603] Ivanti Endpoint Manager AuthHelper Authentication Bypass Vulnerability (CVSS 8.6; Credit: 06fe5fd2bc53027c4a3b7e395af0b850e7b8a044) https://www.zerodayinitiative.com/advisories/ZDI-26-080/

    Post summary

    ZeroDay Initiative has disclosed a new Ivanti Endpoint Manager AuthHelper authentication bypass vulnerability (CVE‑2026‑1603) with a CVSS score of 8.6; no exploit code or patch details are provided in the brief.

    00032577
    5.3K followersView on X
  • ET Labs@ET_Labs
    General

    33 new OPEN, 49 new PRO (33 + 16) ClickFix, Lumma Stealer, CVE-2026-1603 (Ivanti EPM), MacSync, SHubv2.0, TA569, and more. https://community.emergingthreats.net/t/ruleset-update-summary-2026-02-13-v11125/3196

    Post summary

    The text merely lists several new malware names and cites CVE‑2026‑1603 without providing any additional technical, exploit, or mitigation details.

    01130380
    5.7K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1603 - high 🚨 Ivanti Endpoint Manager - Authentication Bypass > Ivanti Endpoint Manager < 2024 SU5 contains an authentication bypass caused by improp... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1603 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-1603, an authentication bypass in Ivanti Endpoint Manager, and links to additional information.

    00022184
    888 followersView on X
  • White Rabbitx@TheRabbitPy
    Active Exploitation

    🚨 CVE-2026-1603 (CVSS 8.6): Ivanti Endpoint Manager auth bypass → creds leak, exploited in wild. MDM creds dumped! https://coastlinecyber.com/cisa-adds-one-known-exploited-vulnerability-to-catalog-92/

    Post summary

    Ivanti Endpoint Manager’s CVE-2026-1603, with a CVSS score of 8.6, is actively exploited in the wild, enabling attackers to bypass authentication and dump MDM credentials.

    0003092
    433 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Ivanti released update for its #Endpoint Manager (EPM) to address #CVE-2026-1603, a high-severity #authentication bypass that allows a remote unauthenticated attacker to access stored credential data, and # CVE-2026-1602, an #SQL injection flaw. https://ccb.belgium.be/advisories/warning-security-update-ivanti-endpoint-manager-vulnerabilities-patch-immediately

    Post summary

    Ivanti released a patch for Endpoint Manager to fix the authentication bypass (CVE‑2026‑1603) and SQL injection (CVE‑2026‑1602) vulnerabilities; users should apply the update immediately.

    02010297
    7.2K followersView on X
  • White Rabbitx@TheRabbitPy
    Active Exploitation

    🚨 CVE-2026-1603 (CVSS 8.6): Ivanti Endpoint Manager auth bypass leaks creds—active exploits confirmed, CISA KEV. MDM compromised! https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html

    Post summary

    The post announces that CVE-2026-1603, an auth bypass in Ivanti Endpoint Manager, is actively exploited in the wild, as confirmed by CISA.

    0101050
    425 followersView on X
  • VulnDex@VulnDex
    Disclosure

    Erhöhte Berichterstattung zu CVE-2026-1603 betrifft Ivanti Endpoint Manager. Ein Authentication Bypass ermöglicht es einem entfernten Angreifer, gespeicherte Zugangsdaten auszulesen. Derzeit ist keine aktive Ausnutzung bekannt. Details & Metriken: https://vulndex.at/cve/CVE-2026-1603 https://t.co/YrNf3MwUBA

    Post summary

    The post announces an authentication bypass vulnerability (CVE‑2026‑1603) in Ivanti Endpoint Manager that permits remote credential disclosure, with no known active exploitation, patches, or PoC provided.

    0101046
    1 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 تحديث CISA لقائمة الثغرات المستغلة (KEV) أضافت CISA ثلاث ثغرات جديدة إلى قائمة الثغرات المستغلة المعروفة (KEV)، وذلك استناداً إلى أدلة تثبت استغلالها النشط في الهجمات. تشمل هذه الثغرات CVE-2026-1603 التي تستهدف Ivanti Endpoint Manager (EPM)، مما يشكل تهديداً مباشراً للأنظمة المعرضة. يؤكد هذا التحديث ضرورة اتخاذ إجراءات فورية للتخفيف من المخاطر. يُنصح المؤسسات بالتحقق من أنظمتها وتطبيق التحديثات الأمنية الخاصة بالثغرات المذكورة ضمن قائمة KEV لتعزيز الدفاعات. 🔗 للمزيد: https://thecyberthrone.in/2026/03/10/cisa-kev-catalog-update-march-9-2026/

    Post summary

    CISA has added CVE-2026-1603 to its KEV list based on evidence of active exploitation, urging users of Ivanti Endpoint Manager to apply patches and mitigate risks immediately.

    00020243
    65 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISA、既知の悪用された脆弱性3件をカタログに追加 CISA Adds Three Known Exploited Vulnerabilities to Catalog #CISA (Mar 9) CVE-2021-22054 Omnissa Workspace ONE サーバー側リクエストフォージェリ CVE-2025-26399 SolarWinds Webヘルプデスクにおける信頼できないデータのデシリアライゼーションの脆弱性 CVE-2026-1603 Ivanti Endpoint Manager (EPM) の認証バイパスの脆弱性 https://www.cisa.gov/news-events/alerts/2026/03/09/cisa-adds-three-known-exploited-vulnerabilities-catalog

    Post summary

    CISA reports adding three CVEs that are actively exploited in the wild, with no PoC, code, patches, or false‑positive claims mentioned.

    00020312
    4.7K followersView on X
  • VulnTracker@vuln_tracker
    General

    @DefusedCyber @watchtowrcyber You can now see the details from https://vulntracker.io/cves/CVE-2026-1603 for free! https://t.co/eNNOwOjJuk

    Post summary

    The tweet simply shares a link to a vulnerability tracker page for CVE‑2026‑1603, offering no further details on the flaw, its exploitation, or remediation.

    01010255
    333 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
Appivantiendpoint_manager---
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--
Appivantiendpoint_manager2024--

Explore more