Ivanti Vulnerabilities
Ivanti sells IT and security software, including the Connect Secure remote access VPN, Endpoint Manager and mobile device management products. The database tracks 38 Ivanti CVE records. CISA lists 36 of them as exploited in the wild, most recently on 2026-06-11. The most affected products are Pulse Connect Secure, Endpoint Manager Mobile (EPMM), Endpoint Manager (EPM).
Recently Exploited Ivanti CVEs
Ivanti Sentry OS Command Injection Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Authentication Bypass
Affected Products
16 products| Product | CVEs | KEV | Latest |
|---|---|---|---|
| Pulse Connect Secure | 8 | 8 | 2022-03-07 |
| Endpoint Manager Mobile (EPMM) | 7 | 7 | 2026-05-07 |
| Endpoint Manager (EPM) | 4 | 4 | 2025-03-10 |
| Cloud Services Appliance (CSA) | 3 | 3 | 2024-10-09 |
| Sentry | 3 | 2 | 2026-06-11 |
| Connect Secure and Policy Secure | 2 | 2 | 2024-01-10 |
| Connect Secure, Policy Secure, and ZTA Gateways | 2 | 2 | 2025-04-04 |
| Endpoint Manager (EPM) | 1 | 1 | 2026-03-09 |
| Cloud Services Appliance | 1 | 1 | 2024-09-13 |
| Connect Secure, Policy Secure, and Neurons | 1 | 1 | 2024-01-31 |
| Endpoint Manager Cloud Service Appliance (EPM CSA) | 1 | 1 | 2024-03-25 |
| Endpoint Manager Mobile | 1 | - | 2026-06-09 |
| Endpoint Manager Mobile (EPMM) and MobileIron Core | 1 | 1 | 2024-01-18 |
| MobileIron Multiple Products | 1 | 1 | 2021-11-03 |
| Pulse Connect Secure and Pulse Policy Secure | 1 | 1 | 2021-11-03 |
| Virtual Traffic Manager | 1 | 1 | 2024-09-24 |
All Ivanti CVEs
38 records| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-10520 | Ivanti Sentry OS Command Injection Vulnerability | ivanti | 10.0 | 99.9% | KEV | 2026-06-09 |
| CVE-2026-6973 | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability | Ivanti | 7.2 | 2.5% | KEV | 2026-05-07 |
| CVE-2026-1340 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | Ivanti | 9.8 | 98.6% | KEV | 2026-01-29 |
| CVE-2026-1603 | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability | Ivanti | 8.6 | 88.3% | KEV | 2026-02-10 |
| CVE-2026-1281 | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | Ivanti | 9.8 | 98.7% | KEV | 2026-01-29 |
| CVE-2025-4427 | Authentication Bypass | Ivanti | 5.3 | 99.9% | KEV | 2025-05-13 |
| CVE-2025-4428 | Remote Code Execution | Ivanti | 7.2 | 86.5% | KEV | 2025-05-13 |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | Ivanti | 9.0 | 100.0% | KEV | 2025-04-03 |
| CVE-2024-13159 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Ivanti | 9.8 | 100.0% | KEV | 2025-01-14 |
| CVE-2024-13160 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Ivanti | 9.8 | 91.2% | KEV | 2025-01-14 |
| CVE-2024-13161 | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | Ivanti | 9.8 | 90.1% | KEV | 2025-01-14 |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | Ivanti | 9.0 | 100.0% | KEV | 2025-01-08 |
| CVE-2024-9380 | Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability | Ivanti | 7.2 | 59.7% | KEV | 2024-10-08 |
| CVE-2024-9379 | Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability | Ivanti | 6.5 | 43.8% | KEV | 2024-10-08 |
| CVE-2024-29824 | Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability | Ivanti | 9.6 | 99.9% | KEV | 2024-05-31 |
| CVE-2024-7593 | Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability | Ivanti | 9.8 | 100.0% | KEV | 2024-08-13 |
| CVE-2024-8963 | Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability | Ivanti | 9.4 | 98.6% | KEV | 2024-09-19 |
| CVE-2024-8190 | Ivanti Cloud Services Appliance OS Command Injection Vulnerability | Ivanti | 7.2 | 88.5% | KEV | 2024-09-10 |
| CVE-2021-44529 | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability | - | 9.8 | 99.1% | KEV | 2021-12-08 |
| CVE-2024-21893 | Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability | Ivanti | 8.2 | 100.0% | KEV | 2024-01-31 |
| CVE-2023-35082 | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability | Ivanti | 10.0 | 100.0% | KEV | 2023-08-15 |
| CVE-2024-21887 | Ivanti Connect Secure and Policy Secure Command Injection Vulnerability | Ivanti | 9.1 | 100.0% | KEV | 2024-01-12 |
| CVE-2023-46805 | Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability | Ivanti | 8.2 | 100.0% | KEV | 2024-01-12 |
| CVE-2023-38035 | Ivanti Sentry Authentication Bypass Vulnerability | Ivanti | 9.8 | 100.0% | KEV | 2023-08-21 |
| CVE-2023-35081 | Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability | Ivanti | 7.2 | 63.6% | KEV | 2023-08-03 |
| CVE-2023-35078 | Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability | Ivanti | 10.0 | 100.0% | KEV | 2023-07-25 |
| CVE-2020-8218 | Pulse Connect Secure Code Injection Vulnerability | - | 7.2 | 32.3% | KEV | 2020-07-30 |
| CVE-2019-11510 | Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability | - | 9.9 | 100.0% | KEV | 2019-05-08 |
| CVE-2020-15505 | Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability | - | 9.8 | 99.7% | KEV | 2020-07-07 |
| CVE-2019-11539 | Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability | - | 8.0 | 98.5% | KEV | 2019-04-26 |
| CVE-2020-8260 | Ivanti Pulse Connect Secure Code Execution Vulnerability | - | 7.2 | 96.5% | KEV | 2020-10-28 |
| CVE-2020-8243 | Ivanti Pulse Connect Secure Code Execution Vulnerability | - | 7.2 | 90.8% | KEV | 2020-09-29 |
| CVE-2021-22893 | Ivanti Pulse Connect Secure Use-After-Free Vulnerability | - | 10.0 | 47.2% | KEV | 2021-04-23 |
| CVE-2021-22894 | Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability | - | 8.8 | 41.3% | KEV | 2021-05-27 |
| CVE-2021-22899 | Ivanti Pulse Connect Secure Command Injection Vulnerability | - | 8.8 | 22.9% | KEV | 2021-05-27 |
| CVE-2021-22900 | Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability | - | 7.2 | 14.1% | KEV | 2021-05-27 |
| CVE-2026-10523 | - | ivanti | 9.9 | 53.1% | 2026-06-09 | |
| CVE-2026-10727 | - | Ivanti | 7.2 | 13.6% | 2026-06-09 |
Frequently Asked Questions
How many Ivanti vulnerabilities are actively exploited?→
36 Ivanti CVEs are in the CISA Known Exploited Vulnerabilities catalog as of 2026-10-09. The latest was added on 2026-06-11.
Which Ivanti vulnerabilities are used in ransomware attacks?→
CISA marks 12 Ivanti KEV entries as known to be used in ransomware campaigns, including CVE-2025-22457, CVE-2025-0282, CVE-2021-44529, CVE-2024-21893, CVE-2023-35082.
Which Ivanti products have the most exploited vulnerabilities?→
- +Pulse Connect Secure: 8 CVEs (8 in KEV)
- +Endpoint Manager Mobile (EPMM): 7 CVEs (7 in KEV)
- +Endpoint Manager (EPM): 4 CVEs (4 in KEV)
- +Cloud Services Appliance (CSA): 3 CVEs (3 in KEV)
- +Sentry: 3 CVEs (2 in KEV)
Where does Ivanti publish security advisories?→
Ivanti publishes security advisories at https://www.ivanti.com/blog/topics/security-advisory. Check the vendor advisory for fixed versions and workarounds before applying updates.
Sources
CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Vendor and product names for exploited CVEs follow the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not affiliated with or endorsed by Ivanti, MITRE, CISA, or FIRST.