Ivanti known exploited vulnerabilities
CISA lists 35 Ivanti CVEs as exploited in the wild. 5 were added in the last 12 months (latest 2026-06-11), and 12 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2024-7593 (Virtual Traffic Manager): EPSS 100.0%, added 2024-09-24
- CVE-2024-21893 (Connect Secure, Policy Secure, and Neurons): EPSS 100.0%, added 2024-01-31
- CVE-2023-35082 (Endpoint Manager Mobile (EPMM) and MobileIron Core): EPSS 100.0%, added 2024-01-18
- CVE-2024-21887 (Connect Secure and Policy Secure): EPSS 100.0%, added 2024-01-10
- CVE-2023-35078 (Endpoint Manager Mobile (EPMM)): EPSS 100.0%, added 2023-07-25
Most affected Ivanti products
Endpoint Manager Mobile (EPMM) (7), Pulse Connect Secure (7), Endpoint Manager (EPM) (4), Cloud Services Appliance (CSA) (3), Sentry (2), Connect Secure, Policy Secure, and ZTA Gateways (2), Connect Secure and Policy Secure (2), Endpoint Manager (EPM) (1), Virtual Traffic Manager (1), Cloud Services Appliance (1), Endpoint Manager Cloud Service Appliance (EPM CSA) (1), Connect Secure, Policy Secure, and Neurons (1).
All Ivanti CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-10520 | Sentry | Sentry OS Command Injection | 2026-06-11 | 2026-06-14 | 99.9% | – |
| CVE-2026-6973 | Endpoint Manager Mobile (EPMM) | Endpoint Manager Mobile (EPMM) Improper Input Validation | 2026-05-07 | 2026-05-10 | 2.5% | – |
| CVE-2026-1340 | Endpoint Manager Mobile (EPMM) | Endpoint Manager Mobile (EPMM) Code Injection | 2026-04-08 | 2026-04-11 | 98.6% | – |
| CVE-2026-1603 | Endpoint Manager (EPM) | Endpoint Manager (EPM) Authentication Bypass | 2026-03-09 | 2026-03-23 | 87.6% | – |
| CVE-2026-1281 | Endpoint Manager Mobile (EPMM) | Endpoint Manager Mobile (EPMM) Code Injection | 2026-01-29 | 2026-02-01 | 98.7% | – |
| CVE-2025-4428 | Endpoint Manager Mobile (EPMM) | Endpoint Manager Mobile (EPMM) Code Injection | 2025-05-19 | 2025-06-09 | 86.5% | – |
| CVE-2025-4427 | Endpoint Manager Mobile (EPMM) | Endpoint Manager Mobile (EPMM) Authentication Bypass | 2025-05-19 | 2025-06-09 | 99.9% | – |
| CVE-2025-22457 | Connect Secure, Policy Secure, and ZTA Gateways | Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow | 2025-04-04 | 2025-04-11 | 100.0% | Yes |
| CVE-2024-13161 | Endpoint Manager (EPM) | Endpoint Manager (EPM) Absolute Path Traversal | 2025-03-10 | 2025-03-31 | 90.1% | – |
| CVE-2024-13160 | Endpoint Manager (EPM) | Endpoint Manager (EPM) Absolute Path Traversal | 2025-03-10 | 2025-03-31 | 91.2% | – |
| CVE-2024-13159 | Endpoint Manager (EPM) | Endpoint Manager (EPM) Absolute Path Traversal | 2025-03-10 | 2025-03-31 | 100.0% | – |
| CVE-2025-0282 | Connect Secure, Policy Secure, and ZTA Gateways | Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow | 2025-01-08 | 2025-01-15 | 100.0% | Yes |
| CVE-2024-9380 | Cloud Services Appliance (CSA) | Cloud Services Appliance (CSA) OS Command Injection | 2024-10-09 | 2024-10-30 | 59.7% | – |
| CVE-2024-9379 | Cloud Services Appliance (CSA) | Cloud Services Appliance (CSA) SQL Injection | 2024-10-09 | 2024-10-30 | 43.8% | – |
| CVE-2024-29824 | Endpoint Manager (EPM) | Endpoint Manager (EPM) SQL Injection | 2024-10-02 | 2024-10-23 | 99.9% | – |
| CVE-2024-7593 | Virtual Traffic Manager | Virtual Traffic Manager Authentication Bypass | 2024-09-24 | 2024-10-15 | 100.0% | – |
| CVE-2024-8963 | Cloud Services Appliance (CSA) | Cloud Services Appliance (CSA) Path Traversal | 2024-09-19 | 2024-10-10 | 98.6% | – |
| CVE-2024-8190 | Cloud Services Appliance | Cloud Services Appliance OS Command Injection | 2024-09-13 | 2024-10-04 | 88.5% | – |
| CVE-2021-44529 | Endpoint Manager Cloud Service Appliance (EPM CSA) | Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection | 2024-03-25 | 2024-04-15 | 99.1% | Yes |
| CVE-2024-21893 | Connect Secure, Policy Secure, and Neurons | Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) | 2024-01-31 | 2024-02-02 | 100.0% | Yes |
| CVE-2023-35082 | Endpoint Manager Mobile (EPMM) and MobileIron Core | Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass | 2024-01-18 | 2024-02-08 | 100.0% | Yes |
| CVE-2024-21887 | Connect Secure and Policy Secure | Connect Secure and Policy Secure Command Injection | 2024-01-10 | 2024-01-22 | 100.0% | Yes |
| CVE-2023-46805 | Connect Secure and Policy Secure | Connect Secure and Policy Secure Authentication Bypass | 2024-01-10 | 2024-01-22 | 100.0% | Yes |
| CVE-2023-38035 | Sentry | Sentry Authentication Bypass | 2023-08-22 | 2023-09-12 | 100.0% | Yes |
| CVE-2023-35081 | Endpoint Manager Mobile (EPMM) | Endpoint Manager Mobile (EPMM) Path Traversal | 2023-07-31 | 2023-08-21 | 63.6% | – |
| CVE-2023-35078 | Endpoint Manager Mobile (EPMM) | Endpoint Manager Mobile Authentication Bypass | 2023-07-25 | 2023-08-15 | 100.0% | Yes |
| CVE-2021-22900 | Pulse Connect Secure | Pulse Connect Secure Unrestricted File Upload | 2021-11-03 | 2022-05-03 | 14.1% | – |
| CVE-2021-22899 | Pulse Connect Secure | Pulse Connect Secure Command Injection | 2021-11-03 | 2022-05-03 | 22.9% | – |
| CVE-2021-22894 | Pulse Connect Secure | Pulse Connect Secure Collaboration Suite Buffer Overflow | 2021-11-03 | 2022-05-03 | 41.3% | – |
| CVE-2021-22893 | Pulse Connect Secure | Pulse Connect Secure Use-After-Free | 2021-11-03 | 2022-05-03 | 47.2% | Yes |
| CVE-2020-8260 | Pulse Connect Secure | Pulse Connect Secure Code Execution | 2021-11-03 | 2022-05-03 | 96.5% | – |
| CVE-2020-8243 | Pulse Connect Secure | Pulse Connect Secure Code Execution | 2021-11-03 | 2022-05-03 | 90.8% | – |
| CVE-2020-15505 | MobileIron Multiple Products | MobileIron Multiple Products Remote Code Execution | 2021-11-03 | 2022-05-03 | 99.7% | – |
| CVE-2019-11539 | Pulse Connect Secure and Pulse Policy Secure | Pulse Connect Secure and Policy Secure Command Injection | 2021-11-03 | 2022-05-03 | 98.5% | Yes |
| CVE-2019-11510 | Pulse Connect Secure | Pulse Connect Secure Arbitrary File Read | 2021-11-03 | 2022-05-03 | 100.0% | Yes |
Read next: Which CVEs to patch first this week · All vendors