Ivanti EPM Vulnerability (CVE-2026-1603) Actively Exploited – Patch Now!

by Anika Shah - Technology
0 comments

CISA Orders Federal Agencies to Patch Actively Exploited Ivanti EPM Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) has flagged a high-severity vulnerability in Ivanti Endpoint Manager (EPM) as actively exploited in attacks, issuing an emergency directive for U.S. Federal agencies to patch systems within three weeks.

Understanding the Vulnerability (CVE-2026-1603)

Ivanti EPM, an all-in-one endpoint management solution used to manage devices across various operating systems including Windows, macOS, Linux, Chrome OS and IoT platforms, is affected by the authentication bypass vulnerability tracked as CVE-2026-1603. This flaw allows remote attackers to bypass authentication and potentially steal credential data without requiring user interaction. The vulnerability is described as a low-complexity cross-site scripting attack.

Patch Availability and Response

Ivanti addressed the vulnerability approximately one month ago with the release of Ivanti EPM 2024 SU5. This update also resolves a separate SQL injection flaw that could allow authenticated attackers to read arbitrary data from the database.

Despite Ivanti stating they had not received reports of exploitation prior to public disclosure through their responsible disclosure program, CISA has added CVE-2026-1603 to its Known Exploited Vulnerabilities (KEV) Catalog, emphasizing the risk posed by such vulnerabilities to the federal enterprise.

Federal Agency Directive

CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies patch their systems by March 23, 2026, in accordance with Binding Operational Directive (BOD) 22-01, issued in November 2021. This directive underscores the seriousness of the threat and the require for immediate action.

Current Exposure

As of March 10, 2026, the Shadowserver threat monitoring platform identifies over 700 Internet-facing Ivanti EPM instances, primarily located in North America. The number of systems still vulnerable to CVE-2026-1603 attacks remains unknown.

Recent Ivanti EPM Vulnerabilities

This is not the first time Ivanti EPM vulnerabilities have been actively exploited. CISA previously warned federal agencies about other EPM flaws exploited in the wild, including CVE-2024-13159, CVE-2024-13160, CVE-2024-13161, and CVE-2024-29824.

Ivanti’s Customer Base

Ivanti serves over 40,000 companies worldwide through a network of more than 7,000 partners.

Protecting Against Exploitation

Administrators using Ivanti Endpoint Manager are strongly advised to update to version 2024 SU5 or later as soon as possible. Check Point provides IPS protection against this vulnerability; administrators should update their Security Gateway product to the latest IPS update and edit the settings for the Ivanti Endpoint Manager Authentication Bypass (CVE-2026-1603) protection. Logs related to this protection will indicate “Attack Name: Web Server Enforcement Violation.”

Related Posts

Leave a Comment