Brand
Ivanti: actively exploited vulnerabilities
36 vulnerabilities in Ivanti products (Connect Secure / Policy Secure (ex-Pulse Secure), Endpoint Manager Mobile (EPMM, ex-MobileIron), Cloud Services Appliance (CSA)…) are in CISA’s catalog of exploited vulnerabilities. Last added: June 11, 2026.
The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).
-
5 vulnerabilities added in the last 12 months
-
36 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
By category
Add just one Ivanti category to your radar, or open its page.
- Monitoring, ITSM and asset management 21 vulnerabilities
- Firewalls, VPNs and remote access 14 vulnerabilities
- Load balancers and access gateways (ADC) 1 vulnerability
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
Affected products
- Connect Secure / Policy Secure (ex-Pulse Secure) 14 vulnerabilities · Firewalls and VPNs
- Endpoint Manager Mobile (EPMM, ex-MobileIron) 9 vulnerabilities · Monitoring and ITSM
- Cloud Services Appliance (CSA) 5 vulnerabilities · Monitoring and ITSM
- Endpoint Manager (EPM) 5 vulnerabilities · Monitoring and ITSM
- Sentry 2 vulnerabilities · Monitoring and ITSM
- Virtual Traffic Manager (vTM) 1 vulnerability · ADCs
Names used by CISA: Ivanti, Pulse Secure. Product families: indicative classification by this site.
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 0 |
| Oct 4, 2025 to Nov 2, 2025 | 0 |
| Nov 3, 2025 to Dec 2, 2025 | 0 |
| Dec 3, 2025 to Jan 1, 2026 | 0 |
| Jan 2, 2026 to Jan 31, 2026 | 1 |
| Feb 1, 2026 to Mar 2, 2026 | 0 |
| Mar 3, 2026 to Apr 1, 2026 | 1 |
| Apr 2, 2026 to May 1, 2026 | 1 |
| May 2, 2026 to May 31, 2026 | 1 |
| Jun 1, 2026 to Jun 30, 2026 | 1 |
| Jul 1, 2026 to Jul 30, 2026 | 0 |
| Jul 31, 2026 to Aug 29, 2026 | 0 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 0 |
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Ivanti list.
Rank 1Ivanti Sentry
CVE-2026-10520Ivanti Sentry OS Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 11, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 2Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2026-1340Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 8, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 3Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2026-1281Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jan 29, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 4Ivanti Endpoint Manager (EPM)
CVE-2026-1603Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 9, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.5 (high)
Rank 5Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 7, 2026
- CISA deadline
- 3 days
- CVSS severity
- 7.2 (high)
Rank 6Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2019-11510RansomwareCVE from 2019, added in 2021
Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 10.0 (critical)
Rank 7Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2021-22893Ransomware
Ivanti Pulse Connect Secure Use-After-Free Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 10.0 (critical)
Rank 8Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2025-22457Ransomware
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Apr 4, 2025
- CISA deadline
- 7 days
- CVSS severity
- 9.8 (critical)
Rank 9Ivanti Virtual Traffic Manager (vTM)
CVE-2024-7593Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 24, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 10Ivanti Cloud Services Appliance (CSA)
CVE-2021-44529RansomwareCVE from 2021, added in 2024
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Show 22 more vulnerabilities
Rank 11Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2023-35082Ransomware
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 12Ivanti Sentry
CVE-2023-38035Ransomware
Ivanti Sentry Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 22, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 13Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2023-35078Ransomware
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 25, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2020-15505Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 15Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2024-21887Ransomware
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 10, 2024
- CISA deadline
- 12 days
- CVSS severity
- 9.1 (critical)
Rank 16Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2025-0282Ransomware
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 8, 2025
- CISA deadline
- 7 days
- CVSS severity
- 9.0 (critical)
Rank 17Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 19, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 18Ivanti Endpoint Manager (EPM)
CVE-2024-29824Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 2, 2024
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 19Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2021-22894Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 20Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2021-22899Ivanti Pulse Connect Secure Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 21Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2024-21893Ransomware
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 31, 2024
- CISA deadline
- 2 days
- CVSS severity
- 8.2 (high)
Rank 22Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2023-46805Ransomware
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 10, 2024
- CISA deadline
- 12 days
- CVSS severity
- 8.2 (high)
Rank 23Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 19, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 24Ivanti Endpoint Manager (EPM)
CVE-2024-13159Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 10, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 25Ivanti Endpoint Manager (EPM)
CVE-2024-13160Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 10, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 26Ivanti Endpoint Manager (EPM)
CVE-2024-13161Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 10, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 27Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 31, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 28Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2020-8218CVE from 2020, added in 2022
Pulse Connect Secure Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2022
- CISA deadline
- 184 days
- CVSS severity
- 7.2 (high)
Rank 29Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2019-11539RansomwareCVE from 2019, added in 2021
Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.2 (high)
Rank 30Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2020-8243Ivanti Pulse Connect Secure Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.2 (high)
Rank 31Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2020-8260Ivanti Pulse Connect Secure Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.2 (high)
Rank 32Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)
CVE-2021-22900Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.2 (high)
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
Ivanti Cloud Services Appliance (CSA)
CVE-2024-9379End of life
Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Oct 9, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Ivanti Cloud Services Appliance (CSA)
CVE-2024-9380End of life
Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Oct 9, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Ivanti Cloud Services Appliance (CSA)
CVE-2024-8963End of life
Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Sep 19, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Ivanti Cloud Services Appliance (CSA)
CVE-2024-8190End of life
Ivanti Cloud Services Appliance OS Command Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Sep 13, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Follow and verify
Get new Ivanti vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.