Skip to content

Products › Brands

Brand

Ivanti: actively exploited vulnerabilities

36 vulnerabilities in Ivanti products (Connect Secure / Policy Secure (ex-Pulse Secure), Endpoint Manager Mobile (EPMM, ex-MobileIron), Cloud Services Appliance (CSA)…) are in CISA’s catalog of exploited vulnerabilities. Last added: June 11, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Ivanti category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

Follow a single Ivanti product (Connect Secure / Policy Secure (ex-Pulse Secure), Endpoint Manager Mobile (EPMM, ex-MobileIron)…) rather than the whole brand.

  • Connect Secure / Policy Secure (ex-Pulse Secure)14 vulnerabilities, Firewalls and VPNs
  • Endpoint Manager Mobile (EPMM, ex-MobileIron)9 vulnerabilities, Monitoring and ITSM
  • Cloud Services Appliance (CSA)5 vulnerabilities, Monitoring and ITSM
  • Endpoint Manager (EPM)5 vulnerabilities, Monitoring and ITSM
  • Sentry2 vulnerabilities, Monitoring and ITSM
  • Virtual Traffic Manager (vTM)1 vulnerability, ADCs

Names used by CISA: Ivanti, Pulse Secure. Product families: indicative classification by this site.

Pace of additions

Number of Ivanti vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on October 3, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 9, 2025 to Oct 8, 20250
Oct 9, 2025 to Nov 7, 20250
Nov 8, 2025 to Dec 7, 20250
Dec 8, 2025 to Jan 6, 20260
Jan 7, 2026 to Feb 5, 20261
Feb 6, 2026 to Mar 7, 20260
Mar 8, 2026 to Apr 6, 20261
Apr 7, 2026 to May 6, 20261
May 7, 2026 to Jun 5, 20261
Jun 6, 2026 to Jul 5, 20261
Jul 6, 2026 to Aug 4, 20260
Aug 5, 2026 to Sep 3, 20260
Sep 4, 2026 to Oct 3, 2026 (in progress)0

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Ivanti list.

  1. Rank 1

    Ivanti SentryCVE-2026-10520

    Ivanti Sentry OS Command Injection Vulnerability

    CVSS severity 10.0critical

    Added Jun 11, 2026

  2. Rank 2

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-1340

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    CVSS severity 9.8critical

    Added Apr 8, 2026

  3. Rank 3

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-1281

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    CVSS severity 9.8critical

    Added Jan 29, 2026

  4. Rank 4

    Ivanti Endpoint Manager (EPM)CVE-2026-1603

    Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

    CVSS severity 7.5high

    Added Mar 9, 2026

  5. Rank 5

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-6973

    Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

    CVSS severity 7.2high

    Added May 7, 2026

  6. Rank 6

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2019-11510

    Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

    RansomwareCVE from 2019, added in 2021

    CVSS severity 10.0critical

    Added Nov 3, 2021

  7. Rank 7

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2021-22893

    Ivanti Pulse Connect Secure Use-After-Free Vulnerability

    Ransomware

    CVSS severity 10.0critical

    Added Nov 3, 2021

  8. Rank 8

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2025-22457

    Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Apr 4, 2025

  9. Rank 9

    Ivanti Virtual Traffic Manager (vTM)CVE-2024-7593

    Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

    CVSS severity 9.8critical

    Added Sep 24, 2024

  10. Rank 10

    Ivanti Cloud Services Appliance (CSA)CVE-2021-44529

    Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

    RansomwareCVE from 2021, added in 2024

    CVSS severity 9.8critical

    Added Mar 25, 2024

Show 22 more vulnerabilities
  1. Rank 11

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35082

    Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jan 18, 2024

  2. Rank 12

    Ivanti SentryCVE-2023-38035

    Ivanti Sentry Authentication Bypass Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Aug 22, 2023

  3. Rank 13

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35078

    Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jul 25, 2023

  4. Rank 14

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2020-15505

    Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  5. Rank 15

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2024-21887

    Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

    Ransomware

    CVSS severity 9.1critical

    Added Jan 10, 2024

  6. Rank 16

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2025-0282

    Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

    Ransomware

    CVSS severity 9.0critical

    Added Jan 8, 2025

  7. Rank 17

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2025-4428

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    CVSS severity 8.8high

    Added May 19, 2025

  8. Rank 18

    Ivanti Endpoint Manager (EPM)CVE-2024-29824

    Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability

    CVSS severity 8.8high

    Added Oct 2, 2024

  9. Rank 19

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2021-22894

    Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

    CVSS severity 8.8high

    Added Nov 3, 2021

  10. Rank 20

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2021-22899

    Ivanti Pulse Connect Secure Command Injection Vulnerability

    CVSS severity 8.8high

    Added Nov 3, 2021

  11. Rank 21

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2024-21893

    Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

    Ransomware

    CVSS severity 8.2high

    Added Jan 31, 2024

  12. Rank 22

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2023-46805

    Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

    Ransomware

    CVSS severity 8.2high

    Added Jan 10, 2024

  13. Rank 23

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2025-4427

    Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

    CVSS severity 7.5high

    Added May 19, 2025

  14. Rank 24

    Ivanti Endpoint Manager (EPM)CVE-2024-13159

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    CVSS severity 7.5high

    Added Mar 10, 2025

  15. Rank 25

    Ivanti Endpoint Manager (EPM)CVE-2024-13160

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    CVSS severity 7.5high

    Added Mar 10, 2025

  16. Rank 26

    Ivanti Endpoint Manager (EPM)CVE-2024-13161

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    CVSS severity 7.5high

    Added Mar 10, 2025

  17. Rank 27

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35081

    Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability

    CVSS severity 7.2high

    Added Jul 31, 2023

  18. Rank 28

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2020-8218

    Pulse Connect Secure Code Injection Vulnerability

    CVE from 2020, added in 2022

    CVSS severity 7.2high

    Added Mar 7, 2022

  19. Rank 29

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2019-11539

    Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

    RansomwareCVE from 2019, added in 2021

    CVSS severity 7.2high

    Added Nov 3, 2021

  20. Rank 30

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2020-8243

    Ivanti Pulse Connect Secure Code Execution Vulnerability

    CVSS severity 7.2high

    Added Nov 3, 2021

  21. Rank 31

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2020-8260

    Ivanti Pulse Connect Secure Code Execution Vulnerability

    CVSS severity 7.2high

    Added Nov 3, 2021

  22. Rank 32

    Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2021-22900

    Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

    CVSS severity 7.2high

    Added Nov 3, 2021

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. Ivanti Cloud Services Appliance (CSA)CVE-2024-9379

    Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability

    End of life

    CVSS severity 7.2high

    Added Oct 9, 2024

  2. Ivanti Cloud Services Appliance (CSA)CVE-2024-9380

    Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability

    End of life

    CVSS severity 7.2high

    Added Oct 9, 2024

  3. Ivanti Cloud Services Appliance (CSA)CVE-2024-8963

    Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

    End of life

    CVSS severity 9.1critical

    Added Sep 19, 2024

  4. Ivanti Cloud Services Appliance (CSA)CVE-2024-8190

    Ivanti Cloud Services Appliance OS Command Injection Vulnerability

    End of life

    CVSS severity 7.2high

    Added Sep 13, 2024

Follow and verify

Get new Ivanti vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.