VDB
CVE-2026-1603
CVE-2026-1603
PUBLISHED
KEV
CVSS 8.600000381469727 HIGH
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
EPSS 58.92% · 98.3th percentile
Risk Scores
CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS Score
58.92%
98.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ivanti | endpoint_manager | 2024, 2024, 2024 |
| Ivanti | Endpoint Manager | *, 2024 SU5 |
Timeline
- Mar 9, 2023 CrowdSec Sighting
- Apr 5, 2023 CrowdSec Sighting
- Apr 9, 2023 CrowdSec Sighting
- Apr 26, 2024 CrowdSec Sighting
- May 21, 2024 CrowdSec Sighting
- May 30, 2024 CrowdSec Sighting
- May 31, 2024 CrowdSec Sighting
- May 31, 2024 CrowdSec Sighting
- Aug 4, 2024 CrowdSec Sighting
- Oct 7, 2024 CrowdSec Sighting
- Jan 5, 2025 CrowdSec Sighting
- Apr 27, 2025 CrowdSec Sighting
References
- https://hub.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024?language=en_US url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-1603 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-1603 advisory
- https://www.ivanti.com/blog/february-2026-security-update advisory
- https://forums.ivanti.com/s/article/Security-Advisory-EPM-February-2026-for-EPM-2024 advisory