Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-1603

97
FAUCET Score

CVE-2026-1603 is a critical authentication bypass vulnerability affecting Ivanti Endpoint Manager versions prior to 2024 SU5. This flaw allows a remote, unauthenticated attacker to leak specific stored credential data. With a CVSS score of 7.5 (High) and low attack complexity, the potential impact on confidentiality is significant. The vulnerability is actively exploited, listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, and has publicly available Nuclei templates, indicating a high probability of exploitation and widespread community attention.

Impacted Technologies

VendorProductVersion(s)CPE
< 2024CPE matchmatch criteria
cpe:2.3:a:ivanti:endpoint_manager:*:*:*:*:*:*:*:*
2024CPE matchmatch criteria
cpe:2.3:a:ivanti:endpoint_manager:2024:-:*:*:*:*:*:*
2024CPE matchmatch criteria
cpe:2.3:a:ivanti:endpoint_manager:2024:su1:*:*:*:*:*:*
2024CPE matchmatch criteria
cpe:2.3:a:ivanti:endpoint_manager:2024:su2:*:*:*:*:*:*
2024CPE matchmatch criteria
cpe:2.3:a:ivanti:endpoint_manager:2024:su3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
80.56%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Mar 9, 2026
Nuclei: CVE-2026-1603 · Feb 13, 2026
This CVE's current EPSS score of 0.8056 is in the 99th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

3cxvendor investigatingvia llm_extracted
amazonvendor investigatingvia llm_extracted
inveniosoftwarevendor investigatingvia llm_extracted
jitsivendor investigatingvia llm_extracted
leantimevendor investigatingvia llm_extracted
nutanixvendor investigatingvia llm_extracted

Vendor Advisories (6)

leantimellm-leantime-983c410b1984f125HIGH

Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)

Feb 15, 2026
amazonllm-amazon-8fcbe196ab5789b9HIGH

Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)

Feb 15, 2026
nutanixllm-nutanix-96d50ad6f3dfe33bHIGH

Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)

Feb 15, 2026
inveniosoftwarellm-inveniosoftware-8010b2f247a69d8aHIGH

Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)

Feb 15, 2026
jitsillm-jitsi-f3e2d3f61de6f04cHIGH

Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)

Feb 15, 2026
3cxllm-3cx-c8cf7cf5e2c0b89cHIGH

Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603)

Feb 15, 2026

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
hub.ivanti.com / s/article/Security-Advisory-EPM-February-2026-for-EPM-2024
Vendor Advisory