Find notable cyber news and cases, enriched with sources, timelines, and signals.

Ivanti Endpoint Manager (EPM) authentication bypass (CVE-2026-1603)

Vulnerability
First reported
Last updated
Happening score
H score 71
1 unique sources, 1 articles

Summary

Hide ▲

A high-severity flaw in Ivanti Endpoint Manager (EPM) is now actively exploited, putting remote unauthenticated attackers in position to bypass authentication and steal credential data. CVE-2026-1603 was added to CISA's KEV Catalog, and FCEB agencies must patch within three weeks by March 23. Ivanti had already fixed the issue in Ivanti EPM 2024 SU5, but exposed systems remain at risk while internet-facing deployments persist.

Related Happenings

CISA Microsoft SharePoint hardening guidance for exploited zero-days

Advisory/Mitigation
H score46 First: 15.07.2026 17:07 Last: 15.07.2026 17:07 Sources 1

About this happening: CISA’s Microsoft SharePoint servers hardening guidance responds to newly disclosed zero-day vulnerabilities that can be exploited remotely, creating immediate risk for sup...

CISA BOD 26-04 SharePoint remediation deadline

Public Sector Action
H score77 First: 15.07.2026 12:44 Last: 15.07.2026 12:44 Sources 1

About this happening: CISA gave federal agencies until July 17 to secure or discontinue SharePoint servers affected by CVE-2026-56164, turning the remediation deadline into a mandatory...

CISA KEV catalog addition for SonicWall SMA 1000 flaws

Public Sector Action
H score34 First: 15.07.2026 08:30 Last: 15.07.2026 08:30 Sources 1

About this happening: CISA added CVE-2026-15409 and CVE-2026-15410 affecting SonicWall SMA 1000 appliances to the KEV catalog, turning the flaws into a federal remediation priority for...

CISA KEV directive for Joomla extension flaws

Public Sector Action
H score36 First: 13.07.2026 18:20 Last: 13.07.2026 18:20 Sources 1

About this happening: CISA added the Joomla extension flaws to the KEV catalog and ordered federal agencies to apply updates or mitigations within three days, tightening remediation tim...

CISA sets June 28 patch deadline for Cisco Unified Communications Manager Server

Public Sector Action
H score35 First: 26.06.2026 22:43 Last: 26.06.2026 22:43 Sources 1

About this happening: CISA ordered federal agencies to patch CVE-2026-20230 in Cisco Unified Communications Manager Server by June 28, tightening exposure around an actively exploited...

Timeline

  1. 10.03.2026 13:36 2 articles · 4mo ago

    CISA adds CVE-2026-1603 to KEV and orders patching

    Legal Policy Action Update

    CISA added CVE-2026-1603 in Ivanti Endpoint Manager (EPM) to the Known Exploited Vulnerabilities (KEV) Catalog and ordered Federal Civilian Executive Branch (FCEB) agencies to patch affected systems within three weeks, by March 23, after describing the flaw as actively exploited and capable of letting remote unauthenticated attackers bypass authentication and steal credential data.

    Show sources