CVE-2026-1603
Ivanti Endpoint Manager vulnerability analysis and mitigation

Overview

CVE-2026-1603 is an authentication bypass vulnerability in Ivanti Endpoint Manager (EPM) that allows a remote unauthenticated attacker to leak specific stored credential data. It affects all EPM 2024 versions prior to 2024 SU5, including 2024 base, SU1, SU2, SU3, SU3 SR1, SU4, SU4 SR1, and SU4 Security Release 1. The vulnerability was first published on February 10, 2026, with Ivanti releasing a patch on February 12, 2026, and CISA adding it to the Known Exploited Vulnerabilities (KEV) catalog on March 9, 2026. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, CISA KEV).

Technical details

The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel) and CWE-306 (Missing Authentication for Critical Function), indicating that a critical function within the EPM AuthHelper component can be reached without proper authentication. An attacker can exploit this remotely over the network with no privileges and no user interaction required, by accessing an alternate path or channel that bypasses the normal authentication controls to extract stored credentials. The vulnerability is internally tracked as affecting the AuthHelper component of Ivanti EPM, as noted in the ZDI advisory ZDI-26-080 (ZDI Advisory, Feedly). A technical deconstruction of the bypass mechanism has been published by security researchers, describing it as a "magic number" authentication bypass (undercodetesting, thecybermind).

Impact

Successful exploitation allows an unauthenticated remote attacker to extract stored credentials from the Ivanti EPM server without any user interaction. Because EPM manages endpoints across enterprise environments, the leaked credentials can be leveraged for lateral movement, privilege escalation, and broader network compromise. The impact is limited to confidentiality (no integrity or availability impact), but the exposure of enterprise credentials significantly amplifies downstream risk (CISA KEV, Feedly).

Exploitability

CVE-2026-1603 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities catalog on March 9, 2026, with a remediation due date of March 23, 2026 for federal agencies (CISA KEV). A ZDI advisory (ZDI-26-080) was published on February 12, 2026, and Horizon3.ai published attack research on the vulnerability (ZDI Advisory, Horizon3.ai). Nuclei detection templates were added to the ProjectDiscovery repository, further lowering the barrier for exploitation (Nuclei Templates). The EPSS score is approximately 0.101 (10.1%), and the vulnerability is flagged as known to be used in ransomware campaign contexts per CISA (CISA KEV, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Ivanti Endpoint Manager instances running versions prior to 2024 SU5 using tools like Shodan, Censys, or Nuclei templates targeting EPM-specific endpoints.
  2. Identify vulnerable endpoint: Locate the AuthHelper component or alternate unauthenticated path within the EPM web interface that bypasses standard authentication controls.
  3. Send unauthenticated request: Craft and send an HTTP request to the vulnerable endpoint using the "magic number" or alternate channel bypass technique, without supplying valid credentials.
  4. Extract stored credentials: The server responds with stored credential data (e.g., service account credentials, managed device credentials) that are accessible due to the missing authentication check.
  5. Leverage credentials for lateral movement: Use the extracted credentials to authenticate to other systems within the enterprise environment, escalate privileges, or pivot to additional targets (ZDI Advisory, thecybermind, Horizon3.ai).

Indicators of compromise

  • Network: Unexpected unauthenticated HTTP/HTTPS requests to Ivanti EPM AuthHelper or credential-related endpoints from external or unknown IP addresses; unusual outbound connections from the EPM server to unknown hosts.
  • Logs: EPM access logs showing requests to authentication bypass paths without valid session tokens or credentials; repeated access attempts to credential storage endpoints from a single source IP.
  • File System: No specific file artifacts reported, but monitor for new files or scripts dropped in EPM installation directories following exploitation.
  • Process: Unusual processes spawned by the EPM service account; unexpected authentication events in Windows Security Event Logs (Event ID 4624/4625) using EPM service account credentials from unfamiliar hosts.
  • Threat Intelligence: Indicators from Beazley Security advisory BSL-A1158 and Field Effect blog may provide additional network-level signatures (Beazley Security, Field Effect).

Mitigation and workarounds

Ivanti has released a patch in Ivanti Endpoint Manager 2024 SU5, which resolves this vulnerability. All organizations running EPM 2024 versions prior to SU5 (including base, SU1, SU2, SU3, SU3 SR1, SU4, SU4 SR1, and SU4 SR1 Security Release) should upgrade immediately. CISA mandated remediation for federal agencies by March 23, 2026, and recommends all organizations apply vendor mitigations or discontinue use if mitigations are unavailable. As an interim measure, consider network segmentation to restrict access to the EPM management interface and monitor for anomalous credential access activity (Ivanti Advisory, CISA KEV).

Community reactions

CISA's addition of CVE-2026-1603 to the KEV catalog on March 9, 2026, generated significant coverage across security media, with BleepingComputer, The Hacker News, SecurityAffairs, and SecurityWeek all reporting on active exploitation (BleepingComputer, The Hacker News). Qualys and Tenable both published detection content, and the Emerging Threats ruleset was updated to include signatures for this CVE (Qualys). Security researchers on Mastodon and Bluesky highlighted the rapid move from patch release to active exploitation, underscoring the urgency of patching Ivanti products. The Record Media noted that CISA shortened the patch deadline for this and related vulnerabilities, reflecting the severity of the threat (The Record).

Additional resources


SourceThis report was generated using AI

Related Ivanti Endpoint Manager vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8111HIGH8.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-8110HIGH7.8
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1603HIGH7.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
YesNoFeb 10, 2026
CVE-2026-8109MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoMay 12, 2026
CVE-2026-1602MEDIUM6.5
  • Ivanti Endpoint Manager logoIvanti Endpoint Manager
  • cpe:2.3:a:ivanti:endpoint_manager
NoNoFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management