Ivanti Endpoint Manager Pre-Auth Credential Leak via Authentication Bypass (CVE-2026-1603)
Ivanti Endpoint Manager Pre-Auth Credential Leak via (TL-2026-0200), also tracked as Ivanti EPM Auth Bypass, is a critical-severity software vulnerability scored CVSS 8.6, first published 2026-03-09. It has no confirmed attribution, affects Ivanti Endpoint Manager, references 1 CVE (CVE-2026-1603), maps to 12 MITRE ATT&CK techniques (T1003, T1021, T1071), and is covered by 9 detection rules and 15 indicators of compromise.
Key facts for TL-2026-0200
- Threat ID
- TL-2026-0200
- Also known as
- Ivanti EPM Auth Bypass, EPM Credential Leak
- Severity
- CRITICAL
- CVSS
- 8.6 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-03-09
- Last reviewed
- 2026-03-09
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- government, financial, healthcare, technology, education, defense, critical-infrastructure, energy, telecommunications
- Target regions
- North America, Europe, Asia Pacific, Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Ivanti Endpoint Manager Pre-Auth Credential Leak via
Malware and tooling: Nuclei
Critical authentication bypass vulnerability in Ivanti Endpoint Manager (EPM) prior to 2024 SU5 allows unauthenticated remote attackers to leak stored credential data via an alternate authentication path. CVSS 8.6, added to CISA KEV on March 9, 2026 with confirmed active exploitation in the wild.
How Ivanti Endpoint Manager Pre-Auth Credential Leak via works
CVE-2026-1603 is an authentication bypass vulnerability in Ivanti Endpoint Manager (EPM) classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The flaw exists in EPM's authentication mechanism where certain API endpoints or administrative functions can be accessed through an alternate path that does not properly enforce authentication requirements. A remote unauthenticated attacker can exploit this vulnerability to leak specific stored credential data from the EPM server.
The vulnerability affects all Ivanti EPM versions prior to 2024 SU5, including the base 2024 release and all service updates through SU4 SR1. The attack requires no user interaction and can be executed remotely over the network without any prior authentication, resulting in a network attack vector with low attack complexity.
The primary impact is to confidentiality — successful exploitation results in the disclosure of stored credential data managed by the EPM platform. Since Ivanti Endpoint Manager is an enterprise endpoint management solution used to manage and secure devices across organizational networks, compromised credentials could enable attackers to pivot to managed endpoints, escalate privileges, and move laterally across the enterprise environment.
The vulnerability was originally reported by Trend Micro's Zero Day Initiative (ZDI) in November 2024. Ivanti published a security advisory and patch (2024 SU5) in February 2026. On March 9, 2026, CISA added CVE-2026-1603 to the Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild.
This vulnerability is part of a broader pattern of critical Ivanti vulnerabilities actively targeted by threat actors. Ivanti products — including EPM, EPMM, Connect Secure, and Policy Secure — have been repeatedly targeted by sophisticated adversaries, including state-sponsored groups. The exploitation of CVE-2026-1603 for credential harvesting aligns with initial access broker operations observed across Ivanti infrastructure, where attackers catalog vulnerable targets and harvest credentials for later compromise or sale.
A companion vulnerability, CVE-2026-1602, is a SQL injection flaw in the same product requiring authentication (CVSS 6.5), and CVE-2025-10573 is a critical stored XSS vulnerability (CVSS 9.6) in EPM versions prior to 2024 SU4 SR1. Organizations running Ivanti EPM should address all three vulnerabilities during remediation.
---
**Revalidated on 2026-03-12**
POST-PUBLICATION ENRICHMENT (2026-03-12):
Exploit Mechanism Confirmed: Independent researchers have confirmed the authentication bypass is triggered by a malformed header concatenation flaw. The exploit uses a 'magic number' value of integer 64 in a crafted HTTP request to bypass authentication controls on credential management endpoints. This allows direct extraction of encrypted credential blobs containing Domain Administrator password hashes and service account credentials from the EPM Credential Vault.
Exposure Surface: Shadowserver Foundation tracks over 700 internet-facing Ivanti EPM instances globally, with the majority concentrated in North America. This represents a significant attack surface for opportunistic exploitation.
Vendor-CISA Discrepancy: While CISA has confirmed active exploitation (KEV listing 2026-03-09), Ivanti has publicly stated they are 'not aware of any customers being exploited by these vulnerabilities prior to public disclosure.' This divergence suggests exploitation may be occurring against organizations that have not reported incidents to Ivanti, or that CISA's intelligence sources have broader visibility into in-the-wild activity.
Related Ivanti Ecosystem Threats: The broader Ivanti product ecosystem is under sustained attack. CVE-2026-1281 and CVE-2026-1340 (Ivanti EPMM, CVSS 9.8) were disclosed 2026-01-29 with public PoC within 24 hours. Unit 42 observed widespread automated exploitation deploying web shells, cryptominers, and persistent backdoors. While these affect EPMM (not EPM), they underscore that attackers are systematically targeting Ivanti infrastructure management products.
NVD CVSS Scoring Note: Ivanti assigns CVSS 8.6 (matching the original record), while NVD lists a score of 7.5. The discrepancy is due to differing scope assessments. The CISA KEV listing and active exploitation status make this distinction largely academic for prioritization purposes.
Qualys Scanner Coverage: QID 386530 is now available for organizations using Qualys for vulnerability management.
MITRE ATT&CK techniques used in TL-2026-0200
credential-access
T1003 OS Credential Dumping; T1552 Unsecured Credentials
lateral-movement
command-and-control
T1071 Application Layer Protocol
defense-evasion
discovery
T1082 System Information Discovery; T1087 Account Discovery
initial-access
T1190 Exploit Public-Facing Application
collection
T1213 Data from Information Repositories
resource-development
reconnaissance
T1595 Active Scanning; T1596 Search Open Technical Databases
Affected products and versions in Ivanti Endpoint Manager Pre-Auth Credential Leak via
- Ivanti — Endpoint Manager
Vulnerable versions: 2024; 2024 SU1; 2024 SU2; 2024 SU3; 2024 SU3 SR1; 2024 SU4; 2024 SU4 SR1
Fixed in: 2024 SU5
Remediation for Ivanti Endpoint Manager Pre-Auth Credential Leak via
Patches
- Ivanti Endpoint Manager 2024 SU5 — fixes CVE-2026-1603 and CVE-2026-1602
- Ivanti Endpoint Manager 2024 SU4 SR1 — fixes CVE-2025-10573 (stored XSS)
Immediate actions
- Upgrade Ivanti Endpoint Manager to version 2024 SU5 or later immediately
- Restrict network access to Ivanti EPM management interfaces to trusted administrative networks only
- Monitor EPM server logs for unauthenticated access attempts to credential-related endpoints
- Block known exploitation source IPs at perimeter firewalls
- Implement web application firewall (WAF) rules to detect authentication bypass attempts
Workarounds
- Restrict EPM management interface access to internal administrative VLANs only
- Enable enhanced logging on EPM servers to detect credential access anomalies
- Deploy reverse proxy with authentication enforcement in front of EPM endpoints
- Monitor for outbound DNS callbacks (OAST) from EPM servers indicating exploitation attempts
Longer-term hardening
- Rotate ALL credentials stored within Ivanti Endpoint Manager as a precautionary measure
- Deploy network segmentation to isolate EPM servers from general network traffic
- Implement continuous vulnerability scanning with SCAP-compliant tools
- Deploy EDR solutions on EPM servers with behavioral detection for credential access
- Establish Ivanti-specific threat intelligence monitoring for emerging vulnerabilities
- Conduct annual external penetration testing of endpoint management infrastructure
CVEs associated with Ivanti Endpoint Manager Pre-Auth Credential Leak via
Weaknesses (CWE) in Ivanti Endpoint Manager Pre-Auth Credential Leak via
CWE-288
Timeline of Ivanti Endpoint Manager Pre-Auth Credential Leak via
- Vulnerability reported to Ivanti by Trend Micro Zero Day Initiative (ZDI)
- CVE-2026-1603 published in NVD and public vulnerability databases
- Ivanti releases Security Advisory EPM-2026-001 and patch via Endpoint Manager 2024 SU5
- Tenable releases detection plugin 298947 for CVE-2026-1603
- Multiple security vendors publish advisories and analysis including CIS, RedLegg, and SentinelOne
- Ivanti updates Security Advisory EPM-2026-001 with additional exploitation details
- CISA adds CVE-2026-1603 alongside SolarWinds and Omnissa Workspace One flaws to KEV catalog in a single batch advisory [Source: https://securityaffairs.com/189172/security/u-s-cisa-adds-ivanti-epm-solarwinds-and-omnissa-workspace-one-flaws-to-its-known-exploited-vulnerabilities-catalog.html]
- Active exploitation confirmed by CISA; threat actors observed targeting unpatched Ivanti EPM instances for credential harvesting
- CISA adds CVE-2026-1603 to Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild
- UnderCode Testing publishes detailed technical walkthrough with video demonstrating the magic number (64) authentication bypass mechanism [Source: https://undercodetesting.com/ivanti-epm-cve-2026-1603-the-magic-number-authentication-bypass-that-exposes-enterprise-devices-video/]
- Qualys ThreatPROTECT publishes full advisory with QID 386530 for CVE-2026-1603 detection [Source: https://threatprotect.qualys.com/2026/03/11/cisa-warns-about-ivanti-epm-vulnerability-exploited-in-attacks-cve-2026-1603/]
- Multiple independent security outlets (BleepingComputer, CyberPress, GBHackers, Field Effect, CSO Online) confirm CISA active exploitation status; Ivanti disputes awareness of customer exploitation prior to disclosure [Source: https://www.bleepingcomputer.com/news/security/cisa-recently-patched-ivanti-epm-flaw-now-actively-exploited/]
- As of 2026-05-29, CVE-2026-1603 (Ivanti EPM auth bypass) remains PATCHED via 2024 SU5 yet still actively exploited; it stays in CISA KEV (added 2026-03-09) and the BOD 22-01 deadline of 2026-03-23 has passed with ~700+ exposed instances. No successor vuln, no actor attribution, and no de-listing or end-of-exploitation reporting found.
Sources cited for Ivanti Endpoint Manager Pre-Auth Credential Leak via
- CISA Known Exploited Vulnerabilities Catalog — CVE-2026-1603
- Ivanti Security Advisory EPM-2026-001 — EPM February 2026
- NVD — CVE-2026-1603
- CIS Advisory — Multiple Vulnerabilities in Ivanti Endpoint Manager
- Security Affairs — Multiple Endpoint Manager Bugs Patched by Ivanti
- Horizon3.ai — CVE-2026-1603 Vulnerability Research
- GreyNoise — Active Ivanti Exploitation Traced to Bulletproof IP
- Tenable — CVE-2026-1603 Detection Plugin 298947
- SentinelOne — CVE-2026-1603 Vulnerability Database Entry
- CyberSecurityNews — Ivanti Endpoint Manager Vulnerability Lets Remote Attacker Leak Arbitrary Data
- RedLegg — Security Bulletin: Authentication Bypass in Ivanti EPM
- CVEFeed — CVE-2026-1603 Detail
Threats related to Ivanti Endpoint Manager Pre-Auth Credential Leak via
Detection coverage for TL-2026-0200
As of 2026-03-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0200 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.