Skip to content
CISA Warns of Active Exploitation of Ivanti EPM Vulnerability CVE-2026-1603

CISA Warns of Active Exploitation of Ivanti EPM Vulnerability CVE-2026-1603

First seen 10 Mar 2026, 11:57 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

CISA has identified a high-severity vulnerability in Ivanti Endpoint Manager (EPM), tracked as CVE-2026-1603, which is currently being exploited in attacks. The flaw allows remote threat actors to bypass authentication and steal credential data, prompting an urgent directive for U.S. federal agencies to patch their systems within three weeks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 210d ago How this analysis works

Timeline

2024-05-31
CVE-2024-29824 published
2025-01-14
CVE-2024-13161 published
2025-01-14
CVE-2024-13159 published
2025-01-14
CVE-2024-13160 published
2026-02-10
CVE-2026-1603 published
2026-03-09
CVE-2026-1603 added to CISA KEV (active exploitation)
2026-03-10
CISA issues patch directive for federal agencies

More articles in this cluster (1)

Following this threat?

Track Ivanti and CVE-2024-13159 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed