A high-severity vulnerability, CVE-2026-1603, exists in Ivanti Endpoint Manager and is described as an authentication bypass that can be exploited by a remote unauthenticated attacker to leak specific stored credential data. NIST records the issue as affecting Ivanti Endpoint Manager releases prior to 2024 SU5 (including 2024 SU4 SR1 and earlier) and assigns a CVSSv3.1 score in the High range (primary 7.5; secondary/alternate scoring up to 8.6). Successful exploitation results in confidentiality loss of stored credentials and may enable further unauthorized access or lateral movement if those credentials are reused or elevated.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

