CISA flags Ivanti EPM vulnerability as actively exploited – federal agencies must patch within 3 weeks
CISA has flagged the high‑severity Ivanti Endpoint Manager (EPM) vulnerability CVE‑2026‑1603 as actively exploited, ordering U.S. federal agencies to patch within three weeks. The flaw allows remote attackers to bypass authentication and steal credentials via low‑complexity cross‑site scripting attacks without user interaction. Although Ivanti released a patch in February 2026 that also addressed an SQL injection flaw, the agency’s alert indicates the vulnerability is now being used in the wild, despite no reported exploitation from Ivanti. The Shadowserver platform tracks over 700 Internet‑exposed EPM instances, primarily in North America, but their current vulnerability status remains unclear. CISA added CVE‑2026‑1603 to its Known Exploited Vulnerabilities catalog and issued a binding directive for federal agencies to patch by March 23. This follows previous advisories on other actively exploited Ivanti EPM flaws, underscoring the ongoing risk of endpoint management software vulnerabilities.







