Skip to content
English

Products › Brands

Brand

Ivanti: actively exploited vulnerabilities

36 vulnerabilities in Ivanti products (Connect Secure / Policy Secure (ex-Pulse Secure), Endpoint Manager Mobile (EPMM, ex-MobileIron), Cloud Services Appliance (CSA)…) are in CISA’s catalog of exploited vulnerabilities. Last added: June 11, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Ivanti category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • Connect Secure / Policy Secure (ex-Pulse Secure) 14 vulnerabilities · Firewalls and VPNs
  • Endpoint Manager Mobile (EPMM, ex-MobileIron) 9 vulnerabilities · Monitoring and ITSM
  • Cloud Services Appliance (CSA) 5 vulnerabilities · Monitoring and ITSM
  • Endpoint Manager (EPM) 5 vulnerabilities · Monitoring and ITSM
  • Sentry 2 vulnerabilities · Monitoring and ITSM
  • Virtual Traffic Manager (vTM) 1 vulnerability · ADCs

Names used by CISA: Ivanti, Pulse Secure. Product families: indicative classification by this site.

Pace of additions

Number of Ivanti vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20250
Oct 4, 2025 to Nov 2, 20250
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20260
Jan 2, 2026 to Jan 31, 20261
Feb 1, 2026 to Mar 2, 20260
Mar 3, 2026 to Apr 1, 20261
Apr 2, 2026 to May 1, 20261
May 2, 2026 to May 31, 20261
Jun 1, 2026 to Jun 30, 20261
Jul 1, 2026 to Jul 30, 20260
Jul 31, 2026 to Aug 29, 20260
Aug 30, 2026 to Sep 28, 2026 (in progress)0

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Ivanti list.

  1. Rank 1Ivanti Sentry

    CVE-2026-10520

    Ivanti Sentry OS Command Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 11, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  2. Rank 2Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2026-1340

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 8, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 3Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2026-1281

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 29, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  4. Rank 4Ivanti Endpoint Manager (EPM)

    CVE-2026-1603

    Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 9, 2026
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  5. Rank 5Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2026-6973

    Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 7, 2026
    CISA deadline
    3 days
    CVSS severity
    7.2 (high)
  6. Rank 6Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2019-11510

    RansomwareCVE from 2019, added in 2021

    Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  7. Rank 7Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22893

    Ransomware

    Ivanti Pulse Connect Secure Use-After-Free Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    10.0 (critical)
  8. Rank 8Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2025-22457

    Ransomware

    Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 4, 2025
    CISA deadline
    7 days
    CVSS severity
    9.8 (critical)
  9. Rank 9Ivanti Virtual Traffic Manager (vTM)

    CVE-2024-7593

    Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 24, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  10. Rank 10Ivanti Cloud Services Appliance (CSA)

    CVE-2021-44529

    RansomwareCVE from 2021, added in 2024

    Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
Show 22 more vulnerabilities
  1. Rank 11Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2023-35082

    Ransomware

    Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 18, 2024
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  2. Rank 12Ivanti Sentry

    CVE-2023-38035

    Ransomware

    Ivanti Sentry Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Aug 22, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  3. Rank 13Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2023-35078

    Ransomware

    Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 25, 2023
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  4. Rank 14Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2020-15505

    Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  5. Rank 15Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2024-21887

    Ransomware

    Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2024
    CISA deadline
    12 days
    CVSS severity
    9.1 (critical)
  6. Rank 16Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2025-0282

    Ransomware

    Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 8, 2025
    CISA deadline
    7 days
    CVSS severity
    9.0 (critical)
  7. Rank 17Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2025-4428

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  8. Rank 18Ivanti Endpoint Manager (EPM)

    CVE-2024-29824

    Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 2, 2024
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  9. Rank 19Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22894

    Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  10. Rank 20Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22899

    Ivanti Pulse Connect Secure Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  11. Rank 21Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2024-21893

    Ransomware

    Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 31, 2024
    CISA deadline
    2 days
    CVSS severity
    8.2 (high)
  12. Rank 22Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2023-46805

    Ransomware

    Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jan 10, 2024
    CISA deadline
    12 days
    CVSS severity
    8.2 (high)
  13. Rank 23Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2025-4427

    Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  14. Rank 24Ivanti Endpoint Manager (EPM)

    CVE-2024-13159

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  15. Rank 25Ivanti Endpoint Manager (EPM)

    CVE-2024-13160

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  16. Rank 26Ivanti Endpoint Manager (EPM)

    CVE-2024-13161

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 10, 2025
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  17. Rank 27Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)

    CVE-2023-35081

    Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 31, 2023
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  18. Rank 28Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2020-8218

    CVE from 2020, added in 2022

    Pulse Connect Secure Code Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 7, 2022
    CISA deadline
    184 days
    CVSS severity
    7.2 (high)
  19. Rank 29Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2019-11539

    RansomwareCVE from 2019, added in 2021

    Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  20. Rank 30Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2020-8243

    Ivanti Pulse Connect Secure Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  21. Rank 31Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2020-8260

    Ivanti Pulse Connect Secure Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)
  22. Rank 32Ivanti Connect Secure / Policy Secure (ex-Pulse Secure)

    CVE-2021-22900

    Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.2 (high)

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-9379

    End of life

    Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Oct 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  2. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-9380

    End of life

    Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Oct 9, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  3. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-8963

    End of life

    Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 19, 2024
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  4. Ivanti Cloud Services Appliance (CSA)

    CVE-2024-8190

    End of life

    Ivanti Cloud Services Appliance OS Command Injection Vulnerability

    End-of-life product: no patch is coming; remove or isolate it.

    Added
    Sep 13, 2024
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)

Follow and verify

Get new Ivanti vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.