Attackers increased exploitation attempts against an authentication bypass flaw in Ivanti Endpoint Manager tracked as CVE-2026-1603, a vulnerability that can let unauthenticated actors gain access and potentially steal user credentials. Ivanti published a security advisory for the affected EPM 2024 product line in February, and the vulnerability was publicly disclosed through the CVE record shortly afterward.
Mitsui Bussan Secure Directions reported that its SOC began observing exploitation attempts on March 13 and saw activity rise further after mid-April. The flaw was also added to CISA's Known Exploited Vulnerabilities catalog on March 9, indicating confirmed in-the-wild abuse, and defenders using affected Ivanti Endpoint Manager deployments were urged to apply the vendor's fixed version without delay.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
MBSD-SOC observed that exploitation activity targeting CVE-2026-1603 increased after mid-April 2026, showing growing attacker interest in the Ivanti Endpoint Manager flaw.
MBSD-SOC reported detecting attacks targeting CVE-2026-1603 beginning on March 13, 2026. Observed requests included POST traffic to /RemoteControlAuth/api/Auth using logintype set to 64 in an apparent authentication bypass attempt.
CISA added CVE-2026-1603 to its Known Exploited Vulnerabilities catalog, indicating confirmed exploitation in the wild.
CVE-2026-1603 was publicly disclosed as an authentication bypass vulnerability in Ivanti Endpoint Manager. Successful exploitation can bypass authentication and may enable theft of user credentials.
Ivanti issued a security advisory for Endpoint Manager 2024 covering CVE-2026-1603, which affects versions earlier than 2024 SU5 and requires upgrading to a fixed release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.