August 2, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-1603NVD

Vulnerability Summary

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
Severity Level
HIGH(8.6)
Published Date
Feb 10, 2026
Last Modified
Mar 10, 2026
Exploitation Status
ACTIVE
EPSS Score (30-Day)
60.88%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone