CVE-2026-1603 is a critical authentication bypass vulnerability affecting Ivanti Endpoint Manager versions prior to 2024 SU5. This flaw allows a remote, unauthenticated attacker to leak specific stored credential data. With a CVSS score of 7.5 (High) and low attack complexity, the potential impact on confidentiality is significant. The vulnerability is actively exploited, listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, and has publicly available Nuclei templates, indicating a high probability of exploitation and widespread community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2024CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:* | ||
2024CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:* | ||
2024CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2024:su1:*:*:*:*:*:* | ||
2024CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2024:su2:*:*:*:*:*:* | ||
2024CPE matchmatch criteria | cpe:2.3:a:ivanti:endpoint_manager:2024:su3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)
Feb 15, 2026Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)
Feb 15, 2026Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)
Feb 15, 2026Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)
Feb 15, 2026Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)
Feb 15, 2026Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)
Feb 15, 2026