Brand
Ivanti: actively exploited vulnerabilities
36 vulnerabilities in Ivanti products (Connect Secure / Policy Secure (ex-Pulse Secure), Endpoint Manager Mobile (EPMM, ex-MobileIron), Cloud Services Appliance (CSA)…) are in CISA’s catalog of exploited vulnerabilities. Last added: June 11, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
5 vulnerabilities added in the last 12 months
-
36 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Ivanti category to your radar, or open its page.
- Monitoring, ITSM and asset management 21 vulnerabilities
- Firewalls, VPNs and remote access 14 vulnerabilities
- Load balancers and access gateways (ADC) 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
Follow a single Ivanti product (Connect Secure / Policy Secure (ex-Pulse Secure), Endpoint Manager Mobile (EPMM, ex-MobileIron)…) rather than the whole brand.
- Connect Secure / Policy Secure (ex-Pulse Secure)14 vulnerabilities, Firewalls and VPNs
- Endpoint Manager Mobile (EPMM, ex-MobileIron)9 vulnerabilities, Monitoring and ITSM
- Cloud Services Appliance (CSA)5 vulnerabilities, Monitoring and ITSM
- Endpoint Manager (EPM)5 vulnerabilities, Monitoring and ITSM
- Sentry2 vulnerabilities, Monitoring and ITSM
- Virtual Traffic Manager (vTM)1 vulnerability, ADCs
Names used by CISA: Ivanti, Pulse Secure. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 9, 2025 to Oct 8, 2025 | 0 |
| Oct 9, 2025 to Nov 7, 2025 | 0 |
| Nov 8, 2025 to Dec 7, 2025 | 0 |
| Dec 8, 2025 to Jan 6, 2026 | 0 |
| Jan 7, 2026 to Feb 5, 2026 | 1 |
| Feb 6, 2026 to Mar 7, 2026 | 0 |
| Mar 8, 2026 to Apr 6, 2026 | 1 |
| Apr 7, 2026 to May 6, 2026 | 1 |
| May 7, 2026 to Jun 5, 2026 | 1 |
| Jun 6, 2026 to Jul 5, 2026 | 1 |
| Jul 6, 2026 to Aug 4, 2026 | 0 |
| Aug 5, 2026 to Sep 3, 2026 | 0 |
| Sep 4, 2026 to Oct 3, 2026 (in progress) | 0 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Ivanti list.
- Rank 1
Ivanti SentryCVE-2026-10520
Ivanti Sentry OS Command Injection Vulnerability
CVSS severity 10.0critical
Added Jun 11, 2026
- Rank 2
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-1340
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVSS severity 9.8critical
Added Apr 8, 2026
- Rank 3
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-1281
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVSS severity 9.8critical
Added Jan 29, 2026
- Rank 4
Ivanti Endpoint Manager (EPM)CVE-2026-1603
Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
CVSS severity 7.5high
Added Mar 9, 2026
- Rank 5
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-6973
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
CVSS severity 7.2high
Added May 7, 2026
- Rank 6
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2019-11510
Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
RansomwareCVE from 2019, added in 2021
CVSS severity 10.0critical
Added Nov 3, 2021
- Rank 7
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2021-22893
Ivanti Pulse Connect Secure Use-After-Free Vulnerability
Ransomware
CVSS severity 10.0critical
Added Nov 3, 2021
- Rank 8
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2025-22457
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Ransomware
CVSS severity 9.8critical
Added Apr 4, 2025
- Rank 9
Ivanti Virtual Traffic Manager (vTM)CVE-2024-7593
Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability
CVSS severity 9.8critical
Added Sep 24, 2024
- Rank 10
Ivanti Cloud Services Appliance (CSA)CVE-2021-44529
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
RansomwareCVE from 2021, added in 2024
CVSS severity 9.8critical
Added Mar 25, 2024
Show 22 more vulnerabilities
- Rank 11
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35082
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jan 18, 2024
- Rank 12
Ivanti SentryCVE-2023-38035
Ivanti Sentry Authentication Bypass Vulnerability
Ransomware
CVSS severity 9.8critical
Added Aug 22, 2023
- Rank 13
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35078
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jul 25, 2023
- Rank 14
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2020-15505
Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 15
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2024-21887
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
Ransomware
CVSS severity 9.1critical
Added Jan 10, 2024
- Rank 16
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2025-0282
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Ransomware
CVSS severity 9.0critical
Added Jan 8, 2025
- Rank 17
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2025-4428
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVSS severity 8.8high
Added May 19, 2025
- Rank 18
Ivanti Endpoint Manager (EPM)CVE-2024-29824
Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability
CVSS severity 8.8high
Added Oct 2, 2024
- Rank 19
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2021-22894
Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability
CVSS severity 8.8high
Added Nov 3, 2021
- Rank 20
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2021-22899
Ivanti Pulse Connect Secure Command Injection Vulnerability
CVSS severity 8.8high
Added Nov 3, 2021
- Rank 21
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2024-21893
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
Ransomware
CVSS severity 8.2high
Added Jan 31, 2024
- Rank 22
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2023-46805
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
Ransomware
CVSS severity 8.2high
Added Jan 10, 2024
- Rank 23
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2025-4427
Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
CVSS severity 7.5high
Added May 19, 2025
- Rank 24
Ivanti Endpoint Manager (EPM)CVE-2024-13159
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
CVSS severity 7.5high
Added Mar 10, 2025
- Rank 25
Ivanti Endpoint Manager (EPM)CVE-2024-13160
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
CVSS severity 7.5high
Added Mar 10, 2025
- Rank 26
Ivanti Endpoint Manager (EPM)CVE-2024-13161
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
CVSS severity 7.5high
Added Mar 10, 2025
- Rank 27
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35081
Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability
CVSS severity 7.2high
Added Jul 31, 2023
- Rank 28
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2020-8218
Pulse Connect Secure Code Injection Vulnerability
CVE from 2020, added in 2022
CVSS severity 7.2high
Added Mar 7, 2022
- Rank 29
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2019-11539
Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
RansomwareCVE from 2019, added in 2021
CVSS severity 7.2high
Added Nov 3, 2021
- Rank 30
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2020-8243
Ivanti Pulse Connect Secure Code Execution Vulnerability
CVSS severity 7.2high
Added Nov 3, 2021
- Rank 31
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2020-8260
Ivanti Pulse Connect Secure Code Execution Vulnerability
CVSS severity 7.2high
Added Nov 3, 2021
- Rank 32
Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)CVE-2021-22900
Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability
CVSS severity 7.2high
Added Nov 3, 2021
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
Ivanti Cloud Services Appliance (CSA)CVE-2024-9379
Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
End of life
CVSS severity 7.2high
Added Oct 9, 2024
Ivanti Cloud Services Appliance (CSA)CVE-2024-9380
Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability
End of life
CVSS severity 7.2high
Added Oct 9, 2024
Ivanti Cloud Services Appliance (CSA)CVE-2024-8963
Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
End of life
CVSS severity 9.1critical
Added Sep 19, 2024
Ivanti Cloud Services Appliance (CSA)CVE-2024-8190
Ivanti Cloud Services Appliance OS Command Injection Vulnerability
End of life
CVSS severity 7.2high
Added Sep 13, 2024
Follow and verify
Get new Ivanti vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.