CyberMax
Home › Exploited CVEs

Ivanti known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 35 Ivanti CVEs as exploited in the wild. 5 were added in the last 12 months (latest 2026-06-11), and 12 are known to be used in ransomware campaigns.

Ivanti CVEs added to CISA KEV per year
2021: 9202192023: 3202332024: 112024112025: 7202572026: 520265

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Ivanti products

Endpoint Manager Mobile (EPMM) (7), Pulse Connect Secure (7), Endpoint Manager (EPM) (4), Cloud Services Appliance (CSA) (3), Sentry (2), Connect Secure, Policy Secure, and ZTA Gateways (2), Connect Secure and Policy Secure (2), Endpoint Manager (EPM) (1), Virtual Traffic Manager (1), Cloud Services Appliance (1), Endpoint Manager Cloud Service Appliance (EPM CSA) (1), Connect Secure, Policy Secure, and Neurons (1).

All Ivanti CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-10520SentrySentry OS Command Injection2026-06-112026-06-1499.9%–
CVE-2026-6973Endpoint Manager Mobile (EPMM)Endpoint Manager Mobile (EPMM) Improper Input Validation2026-05-072026-05-102.5%–
CVE-2026-1340Endpoint Manager Mobile (EPMM)Endpoint Manager Mobile (EPMM) Code Injection2026-04-082026-04-1198.6%–
CVE-2026-1603 Endpoint Manager (EPM)Endpoint Manager (EPM) Authentication Bypass2026-03-092026-03-2387.6%–
CVE-2026-1281Endpoint Manager Mobile (EPMM)Endpoint Manager Mobile (EPMM) Code Injection2026-01-292026-02-0198.7%–
CVE-2025-4428Endpoint Manager Mobile (EPMM)Endpoint Manager Mobile (EPMM) Code Injection2025-05-192025-06-0986.5%–
CVE-2025-4427Endpoint Manager Mobile (EPMM)Endpoint Manager Mobile (EPMM) Authentication Bypass2025-05-192025-06-0999.9%–
CVE-2025-22457Connect Secure, Policy Secure, and ZTA GatewaysConnect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow2025-04-042025-04-11100.0%Yes
CVE-2024-13161Endpoint Manager (EPM)Endpoint Manager (EPM) Absolute Path Traversal2025-03-102025-03-3190.1%–
CVE-2024-13160Endpoint Manager (EPM)Endpoint Manager (EPM) Absolute Path Traversal2025-03-102025-03-3191.2%–
CVE-2024-13159Endpoint Manager (EPM)Endpoint Manager (EPM) Absolute Path Traversal2025-03-102025-03-31100.0%–
CVE-2025-0282Connect Secure, Policy Secure, and ZTA GatewaysConnect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow2025-01-082025-01-15100.0%Yes
CVE-2024-9380Cloud Services Appliance (CSA)Cloud Services Appliance (CSA) OS Command Injection2024-10-092024-10-3059.7%–
CVE-2024-9379Cloud Services Appliance (CSA)Cloud Services Appliance (CSA) SQL Injection2024-10-092024-10-3043.8%–
CVE-2024-29824Endpoint Manager (EPM)Endpoint Manager (EPM) SQL Injection2024-10-022024-10-2399.9%–
CVE-2024-7593Virtual Traffic ManagerVirtual Traffic Manager Authentication Bypass2024-09-242024-10-15100.0%–
CVE-2024-8963Cloud Services Appliance (CSA)Cloud Services Appliance (CSA) Path Traversal2024-09-192024-10-1098.6%–
CVE-2024-8190Cloud Services ApplianceCloud Services Appliance OS Command Injection2024-09-132024-10-0488.5%–
CVE-2021-44529Endpoint Manager Cloud Service Appliance (EPM CSA)Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection2024-03-252024-04-1599.1%Yes
CVE-2024-21893Connect Secure, Policy Secure, and NeuronsConnect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF)2024-01-312024-02-02100.0%Yes
CVE-2023-35082Endpoint Manager Mobile (EPMM) and MobileIron CoreEndpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass2024-01-182024-02-08100.0%Yes
CVE-2024-21887Connect Secure and Policy SecureConnect Secure and Policy Secure Command Injection2024-01-102024-01-22100.0%Yes
CVE-2023-46805Connect Secure and Policy SecureConnect Secure and Policy Secure Authentication Bypass2024-01-102024-01-22100.0%Yes
CVE-2023-38035SentrySentry Authentication Bypass2023-08-222023-09-12100.0%Yes
CVE-2023-35081Endpoint Manager Mobile (EPMM)Endpoint Manager Mobile (EPMM) Path Traversal2023-07-312023-08-2163.6%–
CVE-2023-35078Endpoint Manager Mobile (EPMM)Endpoint Manager Mobile Authentication Bypass2023-07-252023-08-15100.0%Yes
CVE-2021-22900Pulse Connect SecurePulse Connect Secure Unrestricted File Upload2021-11-032022-05-0314.1%–
CVE-2021-22899Pulse Connect SecurePulse Connect Secure Command Injection2021-11-032022-05-0322.9%–
CVE-2021-22894Pulse Connect SecurePulse Connect Secure Collaboration Suite Buffer Overflow2021-11-032022-05-0341.3%–
CVE-2021-22893Pulse Connect SecurePulse Connect Secure Use-After-Free2021-11-032022-05-0347.2%Yes
CVE-2020-8260Pulse Connect SecurePulse Connect Secure Code Execution2021-11-032022-05-0396.5%–
CVE-2020-8243Pulse Connect SecurePulse Connect Secure Code Execution2021-11-032022-05-0390.8%–
CVE-2020-15505MobileIron Multiple ProductsMobileIron Multiple Products Remote Code Execution2021-11-032022-05-0399.7%–
CVE-2019-11539Pulse Connect Secure and Pulse Policy SecurePulse Connect Secure and Policy Secure Command Injection2021-11-032022-05-0398.5%Yes
CVE-2019-11510Pulse Connect SecurePulse Connect Secure Arbitrary File Read2021-11-032022-05-03100.0%Yes
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors