ZeroHour

CVE-2026-1603

KEVlarge

Authentication Bypass in Ivanti Endpoint Manager Leaks Stored Credentials

CISA: Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

CVSS 3.1
7.5 high
EPSS
81%p100
Published
()
KEV added
AI analysis

CVE-2026-1603 is an authentication bypass (CWE-288/CWE-306) in Ivanti Endpoint Manager (EPM) that affects versions before 2024 SU5. A remote, unauthenticated attacker can send crafted network requests to a vulnerable EPM core server without valid credentials. Successful exploitation grants read access to specific stored credential data held by EPM, which could be leveraged for further access within the environment. Any organization running an EPM deployment on a version earlier than 2024 SU5 is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-03-09, confirming active exploitation in the wild, and its EPSS score of 80.6% (100th percentile) indicates a very high likelihood of exploitation in the next 30 days; no public proof-of-concept is known, suggesting private exploit use.

What to do: Upgrade EPM core servers to version 2024 SU5 (or later) as soon as possible, in line with CISA's KEV and BOD 22-01 timelines, which have been shortened for this flaw. Until patched, restrict internet-facing exposure of EPM services and review EPM servers for anomalous authentication activity or signs of stored-credential access. If mitigations are unavailable, follow CISA's guidance to apply vendor-recommended mitigations or discontinue use of the affected product.

Affected
Ivanti Endpoint Manager (EPM)all versions before 2024 SU5
Estimated exposure
largetens of thousands of EPM core-server deployments (order of 10,000–100,000 installations), an estimate — EPM (formerly LANDesk) is a long-established enterprise endpoint-management platform with a substantial installed base in enterprise and government networks, and the flaw affects each deployment's core server rather than each managed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

CISA Known Exploited Vulnerability
Affected
Ivanti Endpoint Manager (EPM)
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
ivanti
Products
endpoint manager
Weakness
CWE-288, CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news