← Browse

CVE-2026-1603

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
80.6%
99.6th percentile
CISA KEV
Listed
Added 2026-03-09 · patch by 2026-03-23
Weakness / dates
Published — · modified —

Timeline

Description

Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data.

Official: NVD · CVE.org