
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1603 is an authentication bypass vulnerability in Ivanti Endpoint Manager (EPM) that allows a remote unauthenticated attacker to leak specific stored credential data. It affects all EPM 2024 versions prior to 2024 SU5, including 2024 base, SU1, SU2, SU3, SU3 SR1, SU4, SU4 SR1, and SU4 Security Release 1. The vulnerability was first published on February 10, 2026, with Ivanti releasing a patch on February 12, 2026, and CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on March 9, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, CISA KEV).
The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and CWE-306 (Missing Authentication for Critical Function), indicating that a critical function within the EPM AuthHelper component can be reached without proper authentication. An attacker can exploit this remotely over the network with no privileges and no user interaction required, by accessing an alternate path or channel that bypasses the normal authentication controls to extract stored credentials. The vulnerability is internally tracked as affecting the AuthHelper component of Ivanti EPM, as noted in the ZDI advisory ZDI-26-080 (ZDI Advisory, Feedly). A technical deconstruction of the bypass mechanism has been published by security researchers, describing it as a "magic number" authentication bypass (undercodetesting, thecybermind).
Successful exploitation allows an unauthenticated remote attacker to extract stored credentials from the Ivanti EPM server without any user interaction. Because EPM manages endpoints across enterprise environments, the leaked credentials can be leveraged for lateral movement, privilege escalation, and broader network compromise. The impact is limited to confidentiality (no integrity or availability impact), but the exposure of enterprise credentials significantly amplifies downstream risk (CISA KEV, Feedly).
CVE-2026-1603 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities catalog on March 9, 2026, with a remediation due date of March 23, 2026 for federal agencies (CISA KEV). A ZDI advisory (ZDI-26-080) was published on February 12, 2026, and Horizon3.ai published attack research on the vulnerability (ZDI Advisory, Horizon3.ai). Nuclei detection templates were added to the ProjectDiscovery repository, further lowering the barrier for exploitation (Nuclei Templates). The EPSS score is approximately 0.101 (10.1%), and the vulnerability is flagged as known to be used in ransomware campaign contexts per CISA (CISA KEV, Feedly).
AuthHelper component or alternate unauthenticated path within the EPM web interface that bypasses standard authentication controls.AuthHelper or credential-related endpoints from external or unknown IP addresses; unusual outbound connections from the EPM server to unknown hosts.Ivanti has released a patch in Ivanti Endpoint Manager 2024 SU5, which resolves this vulnerability. All organizations running EPM 2024 versions prior to SU5 (including base, SU1, SU2, SU3, SU3 SR1, SU4, SU4 SR1, and SU4 SR1 Security Release) should upgrade immediately. CISA mandated remediation for federal agencies by March 23, 2026, and recommends all organizations apply vendor mitigations or discontinue use if mitigations are unavailable. As an interim measure, consider network segmentation to restrict access to the EPM management interface and monitor for anomalous credential access activity (Ivanti Advisory, CISA KEV).
CISA's addition of CVE-2026-1603 to the KEV catalog on March 9, 2026, generated significant coverage across security media, with BleepingComputer, The Hacker News, SecurityAffairs, and SecurityWeek all reporting on active exploitation (BleepingComputer, The Hacker News). Qualys and Tenable both published detection content, and the Emerging Threats ruleset was updated to include signatures for this CVE (Qualys). Security researchers on Mastodon and Bluesky highlighted the rapid move from patch release to active exploitation, underscoring the urgency of patching Ivanti products. The Record Media noted that CISA shortened the patch deadline for this and related vulnerabilities, reflecting the severity of the threat (The Record).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."