Ivanti Endpoint Manager Pre-Auth Credential Leak via Authentication Bypass (CVE-2026-1603)

Ivanti Endpoint Manager Pre-Auth Credential Leak via (TL-2026-0200), also tracked as Ivanti EPM Auth Bypass, is a critical-severity software vulnerability scored CVSS 8.6, first published 2026-03-09. It has no confirmed attribution, affects Ivanti Endpoint Manager, references 1 CVE (CVE-2026-1603), maps to 12 MITRE ATT&CK techniques (T1003, T1021, T1071), and is covered by 9 detection rules and 15 indicators of compromise.

Key facts for TL-2026-0200

Threat ID
TL-2026-0200
Also known as
Ivanti EPM Auth Bypass, EPM Credential Leak
Severity
CRITICAL
CVSS
8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
Status
PATCHED
Category
VULNERABILITY
First published
2026-03-09
Last reviewed
2026-03-09
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
government, financial, healthcare, technology, education, defense, critical-infrastructure, energy, telecommunications
Target regions
North America, Europe, Asia Pacific, Global
Detection rules
9
Indicators of compromise
15

Malware and tooling in Ivanti Endpoint Manager Pre-Auth Credential Leak via

Malware and tooling: Nuclei

Critical authentication bypass vulnerability in Ivanti Endpoint Manager (EPM) prior to 2024 SU5 allows unauthenticated remote attackers to leak stored credential data via an alternate authentication path. CVSS 8.6, added to CISA KEV on March 9, 2026 with confirmed active exploitation in the wild.

How Ivanti Endpoint Manager Pre-Auth Credential Leak via works

CVE-2026-1603 is an authentication bypass vulnerability in Ivanti Endpoint Manager (EPM) classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The flaw exists in EPM's authentication mechanism where certain API endpoints or administrative functions can be accessed through an alternate path that does not properly enforce authentication requirements. A remote unauthenticated attacker can exploit this vulnerability to leak specific stored credential data from the EPM server.

The vulnerability affects all Ivanti EPM versions prior to 2024 SU5, including the base 2024 release and all service updates through SU4 SR1. The attack requires no user interaction and can be executed remotely over the network without any prior authentication, resulting in a network attack vector with low attack complexity.

The primary impact is to confidentiality — successful exploitation results in the disclosure of stored credential data managed by the EPM platform. Since Ivanti Endpoint Manager is an enterprise endpoint management solution used to manage and secure devices across organizational networks, compromised credentials could enable attackers to pivot to managed endpoints, escalate privileges, and move laterally across the enterprise environment.

The vulnerability was originally reported by Trend Micro's Zero Day Initiative (ZDI) in November 2024. Ivanti published a security advisory and patch (2024 SU5) in February 2026. On March 9, 2026, CISA added CVE-2026-1603 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild.

This vulnerability is part of a broader pattern of critical Ivanti vulnerabilities actively targeted by threat actors. Ivanti products — including EPM, EPMM, Connect Secure, and Policy Secure — have been repeatedly targeted by sophisticated adversaries, including state-sponsored groups. The exploitation of CVE-2026-1603 for credential harvesting aligns with initial access broker operations observed across Ivanti infrastructure, where attackers catalog vulnerable targets and harvest credentials for later compromise or sale.

A companion vulnerability, CVE-2026-1602, is a SQL injection flaw in the same product requiring authentication (CVSS 6.5), and CVE-2025-10573 is a critical stored XSS vulnerability (CVSS 9.6) in EPM versions prior to 2024 SU4 SR1. Organizations running Ivanti EPM should address all three vulnerabilities during remediation.

---

**Revalidated on 2026-03-12**

POST-PUBLICATION ENRICHMENT (2026-03-12):

Exploit Mechanism Confirmed: Independent researchers have confirmed the authentication bypass is triggered by a malformed header concatenation flaw. The exploit uses a 'magic number' value of integer 64 in a crafted HTTP request to bypass authentication controls on credential management endpoints. This allows direct extraction of encrypted credential blobs containing Domain Administrator password hashes and service account credentials from the EPM Credential Vault.

Exposure Surface: Shadowserver Foundation tracks over 700 internet-facing Ivanti EPM instances globally, with the majority concentrated in North America. This represents a significant attack surface for opportunistic exploitation.

Vendor-CISA Discrepancy: While CISA has confirmed active exploitation (KEV listing 2026-03-09), Ivanti has publicly stated they are 'not aware of any customers being exploited by these vulnerabilities prior to public disclosure.' This divergence suggests exploitation may be occurring against organizations that have not reported incidents to Ivanti, or that CISA's intelligence sources have broader visibility into in-the-wild activity.

Related Ivanti Ecosystem Threats: The broader Ivanti product ecosystem is under sustained attack. CVE-2026-1281 and CVE-2026-1340 (Ivanti EPMM, CVSS 9.8) were disclosed 2026-01-29 with public PoC within 24 hours. Unit 42 observed widespread automated exploitation deploying web shells, cryptominers, and persistent backdoors. While these affect EPMM (not EPM), they underscore that attackers are systematically targeting Ivanti infrastructure management products.

NVD CVSS Scoring Note: Ivanti assigns CVSS 8.6 (matching the original record), while NVD lists a score of 7.5. The discrepancy is due to differing scope assessments. The CISA KEV listing and active exploitation status make this distinction largely academic for prioritization purposes.

Qualys Scanner Coverage: QID 386530 is now available for organizations using Qualys for vulnerability management.

MITRE ATT&CK techniques used in TL-2026-0200

credential-access

T1003 OS Credential Dumping; T1552 Unsecured Credentials

lateral-movement

T1021 Remote Services

command-and-control

T1071 Application Layer Protocol

defense-evasion

T1078 Valid Accounts

discovery

T1082 System Information Discovery; T1087 Account Discovery

initial-access

T1190 Exploit Public-Facing Application

collection

T1213 Data from Information Repositories

resource-development

T1583 Acquire Infrastructure

reconnaissance

T1595 Active Scanning; T1596 Search Open Technical Databases

Affected products and versions in Ivanti Endpoint Manager Pre-Auth Credential Leak via

  • Ivanti — Endpoint Manager
    Vulnerable versions: 2024; 2024 SU1; 2024 SU2; 2024 SU3; 2024 SU3 SR1; 2024 SU4; 2024 SU4 SR1
    Fixed in: 2024 SU5

Remediation for Ivanti Endpoint Manager Pre-Auth Credential Leak via

Patches

  • Ivanti Endpoint Manager 2024 SU5 — fixes CVE-2026-1603 and CVE-2026-1602
  • Ivanti Endpoint Manager 2024 SU4 SR1 — fixes CVE-2025-10573 (stored XSS)

Immediate actions

  • Upgrade Ivanti Endpoint Manager to version 2024 SU5 or later immediately
  • Restrict network access to Ivanti EPM management interfaces to trusted administrative networks only
  • Monitor EPM server logs for unauthenticated access attempts to credential-related endpoints
  • Block known exploitation source IPs at perimeter firewalls
  • Implement web application firewall (WAF) rules to detect authentication bypass attempts

Workarounds

  • Restrict EPM management interface access to internal administrative VLANs only
  • Enable enhanced logging on EPM servers to detect credential access anomalies
  • Deploy reverse proxy with authentication enforcement in front of EPM endpoints
  • Monitor for outbound DNS callbacks (OAST) from EPM servers indicating exploitation attempts

Longer-term hardening

  • Rotate ALL credentials stored within Ivanti Endpoint Manager as a precautionary measure
  • Deploy network segmentation to isolate EPM servers from general network traffic
  • Implement continuous vulnerability scanning with SCAP-compliant tools
  • Deploy EDR solutions on EPM servers with behavioral detection for credential access
  • Establish Ivanti-specific threat intelligence monitoring for emerging vulnerabilities
  • Conduct annual external penetration testing of endpoint management infrastructure

CVEs associated with Ivanti Endpoint Manager Pre-Auth Credential Leak via

CVE-2026-1603

Weaknesses (CWE) in Ivanti Endpoint Manager Pre-Auth Credential Leak via

CWE-288

Timeline of Ivanti Endpoint Manager Pre-Auth Credential Leak via

  • Vulnerability reported to Ivanti by Trend Micro Zero Day Initiative (ZDI)
  • CVE-2026-1603 published in NVD and public vulnerability databases
  • Ivanti releases Security Advisory EPM-2026-001 and patch via Endpoint Manager 2024 SU5
  • Tenable releases detection plugin 298947 for CVE-2026-1603
  • Multiple security vendors publish advisories and analysis including CIS, RedLegg, and SentinelOne
  • Ivanti updates Security Advisory EPM-2026-001 with additional exploitation details
  • CISA adds CVE-2026-1603 alongside SolarWinds and Omnissa Workspace One flaws to KEV catalog in a single batch advisory [Source: https://securityaffairs.com/189172/security/u-s-cisa-adds-ivanti-epm-solarwinds-and-omnissa-workspace-one-flaws-to-its-known-exploited-vulnerabilities-catalog.html]
  • Active exploitation confirmed by CISA; threat actors observed targeting unpatched Ivanti EPM instances for credential harvesting
  • CISA adds CVE-2026-1603 to Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild
  • UnderCode Testing publishes detailed technical walkthrough with video demonstrating the magic number (64) authentication bypass mechanism [Source: https://undercodetesting.com/ivanti-epm-cve-2026-1603-the-magic-number-authentication-bypass-that-exposes-enterprise-devices-video/]
  • Qualys ThreatPROTECT publishes full advisory with QID 386530 for CVE-2026-1603 detection [Source: https://threatprotect.qualys.com/2026/03/11/cisa-warns-about-ivanti-epm-vulnerability-exploited-in-attacks-cve-2026-1603/]
  • Multiple independent security outlets (BleepingComputer, CyberPress, GBHackers, Field Effect, CSO Online) confirm CISA active exploitation status; Ivanti disputes awareness of customer exploitation prior to disclosure [Source: https://www.bleepingcomputer.com/news/security/cisa-recently-patched-ivanti-epm-flaw-now-actively-exploited/]
  • As of 2026-05-29, CVE-2026-1603 (Ivanti EPM auth bypass) remains PATCHED via 2024 SU5 yet still actively exploited; it stays in CISA KEV (added 2026-03-09) and the BOD 22-01 deadline of 2026-03-23 has passed with ~700+ exposed instances. No successor vuln, no actor attribution, and no de-listing or end-of-exploitation reporting found.

Sources cited for Ivanti Endpoint Manager Pre-Auth Credential Leak via

Threats related to Ivanti Endpoint Manager Pre-Auth Credential Leak via

Detection coverage for TL-2026-0200

As of 2026-03-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0200 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats