Skip to content

Products › IT administration and security

IT administration and security

Monitoring, ITSM and asset management

Monitoring, ticketing, inventory, software deployment and mobile device management (MDM) tools.

For example: Ivanti EPMM, ManageEngine, SolarWinds, Nagios.

Category RSS feed

Pace of additions

Number of “Monitoring and ITSM” vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on October 3, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 9, 2025 to Oct 8, 20250
Oct 9, 2025 to Nov 7, 20253
Nov 8, 2025 to Dec 7, 20250
Dec 8, 2025 to Jan 6, 20260
Jan 7, 2026 to Feb 5, 20263
Feb 6, 2026 to Mar 7, 20263
Mar 8, 2026 to Apr 6, 20264
Apr 7, 2026 to May 6, 20263
May 7, 2026 to Jun 5, 20261
Jun 6, 2026 to Jul 5, 20261
Jul 6, 2026 to Aug 4, 20260
Aug 5, 2026 to Sep 3, 20260
Sep 4, 2026 to Oct 3, 2026 (in progress)0

Affected brands

In alphabetical order, with their number of vulnerabilities in this category.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

See also

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.

  1. Rank 1

    Ivanti SentryCVE-2026-10520

    Ivanti Sentry OS Command Injection Vulnerability

    CVSS severity 10.0critical

    Added Jun 11, 2026

  2. Rank 2

    Quest KACE Systems Management Appliance (SMA)CVE-2025-32975

    Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability

    CVSS severity 10.0critical

    Added Apr 20, 2026

  3. Rank 3

    Fortinet FortiClient EMSCVE-2026-21643

    Fortinet FortiClient EMS SQL Injection Vulnerability

    CVSS severity 9.8critical

    Added Apr 13, 2026

  4. Rank 4

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-1340

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    CVSS severity 9.8critical

    Added Apr 8, 2026

  5. Rank 5

    Fortinet FortiClient EMSCVE-2026-35616

    Fortinet FortiClient EMS Improper Access Control Vulnerability

    CVSS severity 9.8critical

    Added Apr 6, 2026

  6. Rank 6

    SolarWinds Web Help DeskCVE-2025-26399

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Mar 9, 2026

  7. Rank 7

    Microsoft Configuration ManagerCVE-2024-43468

    Microsoft Configuration Manager SQL Injection Vulnerability

    CVE from 2024, added in 2026

    CVSS severity 9.8critical

    Added Feb 12, 2026

  8. Rank 8

    SolarWinds Web Help DeskCVE-2025-40536

    SolarWinds Web Help Desk Security Control Bypass Vulnerability

    CVSS severity 9.8critical

    Added Feb 12, 2026

  9. Rank 9

    SolarWinds Web Help DeskCVE-2025-40551

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    CVSS severity 9.8critical

    Added Feb 3, 2026

  10. Rank 10

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-1281

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    CVSS severity 9.8critical

    Added Jan 29, 2026

Show 64 more vulnerabilities
  1. Rank 11

    HPE OneViewCVE-2025-37164

    Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability

    CVSS severity 9.8critical

    Added Jan 7, 2026

  2. Rank 12

    Motex LANSCOPE Endpoint ManagerCVE-2025-61932

    Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability

    CVSS severity 9.8critical

    Added Oct 22, 2025

  3. Rank 13

    SKYSEA Client ViewCVE-2016-7836

    SKYSEA Client View Improper Authentication Vulnerability

    CVE from 2016, added in 2025

    CVSS severity 9.8critical

    Added Oct 14, 2025

  4. Rank 14

    VMware (Broadcom) Aria Operations (ex-vRealize Operations)CVE-2026-22719

    Broadcom VMware Aria Operations Command Injection Vulnerability

    CVSS severity 8.1high

    Added Mar 3, 2026

  5. Rank 15

    Omnissa (ex-VMware EUC) Workspace ONE UEM (AirWatch)CVE-2021-22054

    Omnissa Workspace ONE Server-Side Request Forgery

    CVE from 2021, added in 2026

    CVSS severity 7.5high

    Added Mar 9, 2026

  6. Rank 16

    Ivanti Endpoint Manager (EPM)CVE-2026-1603

    Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

    CVSS severity 7.5high

    Added Mar 9, 2026

  7. Rank 17

    Grafana Labs GrafanaCVE-2021-43798

    Grafana Path Traversal Vulnerability

    CVE from 2021, added in 2025

    CVSS severity 7.5high

    Added Oct 9, 2025

  8. Rank 18

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-6973

    Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

    CVSS severity 7.2high

    Added May 7, 2026

  9. Rank 19

    SysAid On-PremCVE-2025-2776

    SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

    CVSS severity 9.8critical

    Added Jul 22, 2025

  10. Rank 20

    Cisco Smart Licensing UtilityCVE-2024-20439

    Cisco Smart Licensing Utility Static Credential Vulnerability

    CVSS severity 9.8critical

    Added Mar 31, 2025

  11. Rank 21

    Progress WhatsUp GoldCVE-2024-4885

    Progress WhatsUp Gold Path Traversal Vulnerability

    CVSS severity 9.8critical

    Added Mar 3, 2025

  12. Rank 22

    Paessler PRTG Network MonitorCVE-2018-19410

    Paessler PRTG Network Monitor Local File Inclusion Vulnerability

    CVE from 2018, added in 2025

    CVSS severity 9.8critical

    Added Feb 4, 2025

  13. Rank 23

    ScienceLogic SL1CVE-2024-9537

    ScienceLogic SL1 Unspecified Vulnerability

    CVSS severity 9.8critical

    Added Oct 21, 2024

  14. Rank 24

    Progress WhatsUp GoldCVE-2024-6670

    Progress WhatsUp Gold SQL Injection Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Sep 16, 2024

  15. Rank 25

    SolarWinds Web Help DeskCVE-2024-28986

    SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

    CVSS severity 9.8critical

    Added Aug 15, 2024

  16. Rank 26

    ServiceNow Now PlatformCVE-2024-4879

    ServiceNow Improper Input Validation Vulnerability

    CVSS severity 9.8critical

    Added Jul 29, 2024

  17. Rank 27

    ServiceNow Now PlatformCVE-2024-5217

    ServiceNow Incomplete List of Disallowed Inputs Vulnerability

    CVSS severity 9.8critical

    Added Jul 29, 2024

  18. Rank 28

    Ivanti Cloud Services Appliance (CSA)CVE-2021-44529

    Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

    RansomwareCVE from 2021, added in 2024

    CVSS severity 9.8critical

    Added Mar 25, 2024

  19. Rank 29

    Fortinet FortiClient EMSCVE-2023-48788

    Fortinet FortiClient EMS SQL Injection Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Mar 25, 2024

  20. Rank 30

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35082

    Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jan 18, 2024

  21. Rank 31

    SysAid On-PremCVE-2023-47246

    SysAid Server Path Traversal Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Nov 13, 2023

  22. Rank 32

    Ivanti SentryCVE-2023-38035

    Ivanti Sentry Authentication Bypass Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Aug 22, 2023

  23. Rank 33

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35078

    Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jul 25, 2023

  24. Rank 34

    VMware (Broadcom) Aria Operations for Networks (ex-vRealize Network Insight)CVE-2023-20887

    Vmware Aria Operations for Networks Command Injection Vulnerability

    CVSS severity 9.8critical

    Added Jun 22, 2023

  25. Rank 35

    Teclib GLPICVE-2022-35914

    Teclib GLPI Remote Code Execution Vulnerability

    CVSS severity 9.8critical

    Added Mar 7, 2023

  26. Rank 36

    CactiCVE-2022-46169

    Cacti Command Injection Vulnerability

    CVSS severity 9.8critical

    Added Feb 16, 2023

  27. Rank 37

    ManageEngine (Zoho) Multiple productsCVE-2022-47966

    Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability

    Ransomware

    CVSS severity 9.8critical

    Added Jan 23, 2023

  28. Rank 38

    HPE Network Node Manager (OpenView NNM)CVE-2005-2773

    HP OpenView Network Node Manager Remote Code Execution Vulnerability

    CVE from 2005, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  29. Rank 39

    HPE ProCurve Manager (PCM, PCM+, IDM)CVE-2013-4810

    HP Multiple Products Remote Code Execution Vulnerability

    CVE from 2013, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  30. Rank 40

    Quest KACE Systems Management Appliance (SMA)CVE-2018-11138

    Quest KACE System Management Appliance Remote Command Execution Vulnerability

    RansomwareCVE from 2018, added in 2022

    CVSS severity 9.8critical

    Added Mar 25, 2022

  31. Rank 41

    Zabbix FrontendCVE-2022-23131

    Zabbix Frontend Authentication Bypass Vulnerability

    CVSS severity 9.8critical

    Added Feb 22, 2022

  32. Rank 42

    ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)CVE-2021-44515

    Zoho Desktop Central Authentication Bypass Vulnerability

    CVSS severity 9.8critical

    Added Dec 10, 2021

  33. Rank 43

    ManageEngine (Zoho) ServiceDesk PlusCVE-2021-37415

    Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability

    CVSS severity 9.8critical

    Added Dec 1, 2021

  34. Rank 44

    ManageEngine (Zoho) ServiceDesk PlusCVE-2021-44077

    Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability

    CVSS severity 9.8critical

    Added Dec 1, 2021

  35. Rank 45

    SolarWinds Orion PlatformCVE-2020-10148

    SolarWinds Orion Authentication Bypass Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  36. Rank 46

    ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)CVE-2020-10189

    Zoho ManageEngine Desktop Central File Upload Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  37. Rank 47

    SaltStack SaltCVE-2020-11651

    SaltStack Salt Authentication Bypass Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  38. Rank 48

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2020-15505

    Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  39. Rank 49

    SaltStack SaltCVE-2020-16846

    SaltStack Salt Shell Injection Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  40. Rank 50

    EyesOfNetworkCVE-2020-8657

    EyesOfNetwork Use of Hard-Coded Credentials Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  41. Rank 51

    OpenText (Micro Focus) Operations Bridge Reporter (OBR)CVE-2021-22502

    Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

    CVSS severity 9.8critical

    Added Nov 3, 2021

  42. Rank 52

    SolarWinds Web Help DeskCVE-2024-28987

    SolarWinds Web Help Desk Hardcoded Credential Vulnerability

    CVSS severity 9.1critical

    Added Oct 15, 2024

  43. Rank 53

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2025-4428

    Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

    CVSS severity 8.8high

    Added May 19, 2025

  44. Rank 54

    Ivanti Endpoint Manager (EPM)CVE-2024-29824

    Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability

    CVSS severity 8.8high

    Added Oct 2, 2024

  45. Rank 55

    Nagios XICVE-2021-25296

    Nagios XI OS Command Injection

    CVSS severity 8.8high

    Added Jan 18, 2022

  46. Rank 56

    Nagios XICVE-2021-25297

    Nagios XI OS Command Injection

    CVSS severity 8.8high

    Added Jan 18, 2022

  47. Rank 57

    Nagios XICVE-2021-25298

    Nagios XI OS Command Injection

    CVSS severity 8.8high

    Added Jan 18, 2022

  48. Rank 58

    Nagios XICVE-2019-15949

    Nagios XI Remote Code Execution Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 8.8high

    Added Nov 3, 2021

  49. Rank 59

    rConfigCVE-2020-10221

    rConfig OS Command Injection Vulnerability

    CVSS severity 8.8high

    Added Nov 3, 2021

  50. Rank 60

    SolarWinds Virtualization ManagerCVE-2016-3643

    SolarWinds Virtualization Manager Privilege Escalation Vulnerability

    CVE from 2016, added in 2021

    CVSS severity 7.8high

    Added Nov 3, 2021

  51. Rank 61

    EyesOfNetworkCVE-2020-8655

    EyesOfNetwork Improper Privilege Management Vulnerability

    CVSS severity 7.8high

    Added Nov 3, 2021

  52. Rank 62

    SysAid On-PremCVE-2025-2775

    SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability

    CVSS severity 7.5high

    Added Jul 22, 2025

  53. Rank 63

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2025-4427

    Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

    CVSS severity 7.5high

    Added May 19, 2025

  54. Rank 64

    Ivanti Endpoint Manager (EPM)CVE-2024-13159

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    CVSS severity 7.5high

    Added Mar 10, 2025

  55. Rank 65

    Ivanti Endpoint Manager (EPM)CVE-2024-13160

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    CVSS severity 7.5high

    Added Mar 10, 2025

  56. Rank 66

    Ivanti Endpoint Manager (EPM)CVE-2024-13161

    Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

    CVSS severity 7.5high

    Added Mar 10, 2025

  57. Rank 67

    Cisco Prime Data Center Network Manager (DCNM)CVE-2015-0666

    Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability

    CVE from 2015, added in 2022

    CVSS severity 7.5high

    Added Mar 25, 2022

  58. Rank 68

    VMware (Broadcom) Aria Operations (ex-vRealize Operations)CVE-2021-21975

    VMware Server Side Request Forgery in vRealize Operations Manager API

    Ransomware

    CVSS severity 7.5high

    Added Jan 18, 2022

  59. Rank 69

    Grafana Labs GrafanaCVE-2021-39226

    Grafana Authentication Bypass Vulnerability

    CVSS severity 7.3high

    Added Aug 25, 2022

  60. Rank 70

    Paessler PRTG Network MonitorCVE-2018-9276

    Paessler PRTG Network Monitor OS Command Injection Vulnerability

    CVE from 2018, added in 2025

    CVSS severity 7.2high

    Added Feb 4, 2025

  61. Rank 71

    Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35081

    Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability

    CVSS severity 7.2high

    Added Jul 31, 2023

  62. Rank 72

    ManageEngine (Zoho) ServiceDesk PlusCVE-2019-8394

    Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability

    CVE from 2019, added in 2021

    CVSS severity 6.5medium

    Added Nov 3, 2021

  63. Rank 73

    SaltStack SaltCVE-2020-11652

    SaltStack Salt Path Traversal Vulnerability

    CVSS severity 6.5medium

    Added Nov 3, 2021

  64. Rank 74

    Zabbix FrontendCVE-2022-23134

    Zabbix Frontend Improper Access Control Vulnerability

    CVSS severity 5.3medium

    Added Feb 22, 2022

Filed under another category

These 2 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.

  1. Microsoft WindowsCVE-2025-59287

    Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

    CVSS severity 9.8critical

    Added Oct 24, 2025

  2. VMware (Broadcom) VMware ToolsCVE-2025-41244

    Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability

    CVSS severity 7.8high

    Added Oct 30, 2025

End of life: remove

These products are no longer supported: no patch is coming. Remove them or isolate them from the network.

  1. Ivanti Cloud Services Appliance (CSA)CVE-2024-9379

    Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability

    End of life

    CVSS severity 7.2high

    Added Oct 9, 2024

  2. Ivanti Cloud Services Appliance (CSA)CVE-2024-9380

    Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability

    End of life

    CVSS severity 7.2high

    Added Oct 9, 2024

  3. Ivanti Cloud Services Appliance (CSA)CVE-2024-8963

    Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

    End of life

    CVSS severity 9.1critical

    Added Sep 19, 2024

  4. Ivanti Cloud Services Appliance (CSA)CVE-2024-8190

    Ivanti Cloud Services Appliance OS Command Injection Vulnerability

    End of life

    CVSS severity 7.2high

    Added Sep 13, 2024

Follow and verify

Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.