How we count
Every figure on this page is a direct count of entries in CISA’s Known Exploited Vulnerabilities catalog attributed by CISA to Ivanti (KEV field vendorProject), refreshed daily. “Ransomware-linked” counts entries CISA marks as known to be used in ransomware campaigns; the remainder are “unknown” to CISA, not confirmed ransomware-free. A KEV listing means the vulnerability has been observed exploited in the wild. Snapshot as of 2026-08-31.
Exploited Ivanti vulnerabilities (CISA KEV)
| CVE | Product | Vulnerability | Added | |
|---|---|---|---|---|
| CVE-2026-10520 | Sentry | Ivanti Sentry OS Command Injection Vulnerability | 2026-06-11 | |
| CVE-2026-6973 | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability | 2026-05-07 | |
| CVE-2026-1340 | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | 2026-04-08 | |
| CVE-2026-1603 | Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability | 2026-03-09 | |
| CVE-2026-1281 | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | 2026-01-29 | |
| CVE-2025-4428 | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability | 2025-05-19 | |
| CVE-2025-4427 | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability | 2025-05-19 | |
| CVE-2025-22457 | Connect Secure, Policy Secure, and ZTA Gateways | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | 2025-04-04 | ransomware |
| CVE-2024-13161 | Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 2025-03-10 | |
| CVE-2024-13160 | Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 2025-03-10 | |
| CVE-2024-13159 | Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability | 2025-03-10 | |
| CVE-2025-0282 | Connect Secure, Policy Secure, and ZTA Gateways | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | 2025-01-08 | ransomware |
| CVE-2024-9380 | Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability | 2024-10-09 | |
| CVE-2024-9379 | Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability | 2024-10-09 | |
| CVE-2024-29824 | Endpoint Manager (EPM) | Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability | 2024-10-02 | |
| CVE-2024-7593 | Virtual Traffic Manager | Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability | 2024-09-24 | |
| CVE-2024-8963 | Cloud Services Appliance (CSA) | Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability | 2024-09-19 | |
| CVE-2024-8190 | Cloud Services Appliance | Ivanti Cloud Services Appliance OS Command Injection Vulnerability | 2024-09-13 | |
| CVE-2021-44529 | Endpoint Manager Cloud Service Appliance (EPM CSA) | Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability | 2024-03-25 | ransomware |
| CVE-2024-21893 | Connect Secure, Policy Secure, and Neurons | Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability | 2024-01-31 | ransomware |
| CVE-2023-35082 | Endpoint Manager Mobile (EPMM) and MobileIron Core | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability | 2024-01-18 | ransomware |
| CVE-2023-46805 | Connect Secure and Policy Secure | Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability | 2024-01-10 | ransomware |
| CVE-2024-21887 | Connect Secure and Policy Secure | Ivanti Connect Secure and Policy Secure Command Injection Vulnerability | 2024-01-10 | ransomware |
| CVE-2023-38035 | Sentry | Ivanti Sentry Authentication Bypass Vulnerability | 2023-08-22 | ransomware |
| CVE-2023-35081 | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability | 2023-07-31 | |
| CVE-2023-35078 | Endpoint Manager Mobile (EPMM) | Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability | 2023-07-25 | ransomware |
| CVE-2020-15505 | MobileIron Multiple Products | Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability | 2021-11-03 | |
| CVE-2021-22893 | Pulse Connect Secure | Ivanti Pulse Connect Secure Use-After-Free Vulnerability | 2021-11-03 | ransomware |
| CVE-2020-8243 | Pulse Connect Secure | Ivanti Pulse Connect Secure Code Execution Vulnerability | 2021-11-03 | |
| CVE-2021-22900 | Pulse Connect Secure | Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability | 2021-11-03 | |
| CVE-2021-22894 | Pulse Connect Secure | Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability | 2021-11-03 | |
| CVE-2020-8260 | Pulse Connect Secure | Ivanti Pulse Connect Secure Code Execution Vulnerability | 2021-11-03 | |
| CVE-2021-22899 | Pulse Connect Secure | Ivanti Pulse Connect Secure Command Injection Vulnerability | 2021-11-03 | |
| CVE-2019-11510 | Pulse Connect Secure | Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability | 2021-11-03 | ransomware |
| CVE-2019-11539 | Pulse Connect Secure and Pulse Policy Secure | Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability | 2021-11-03 | ransomware |
← All vendors by exploited-vulnerability count
🤖 Generated by defend.network from the CISA KEV catalog. Counts are deterministic aggregates of official CISA data; verify individual advisories at the linked sources.