Ivanti vendor intelligence

Ivanti Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting Ivanti products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Browse Ivanti KEVs Full KEV feed
Total KEVs
30
Known exploited vulnerabilities affecting Ivanti products
In CISA KEV
26
Records also listed in the official catalog
Beyond CISA KEV
4
Additional exploited CVEs absent from CISA KEV
Sensor Observed
3
Ivanti KEVs with sensor-observed exploitation activity

The catalog gap matters for Ivanti exposure

Four of the 30 exploited Ivanti CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 13% of this vendor portfolio.

87%
Covered by CISA
13%
Beyond CISA
12
Product families

Attested Ivanti CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2026-10520

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to...

Sentry Confirmed In CISA 10 Jun 2026
CVE-2024-38653

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

Avalanche High Beyond CISA 05 Sep 2025
CVE-2021-30497

Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath...

Avalanche High Beyond CISA 16 Jul 2025
CVE-2026-6973

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user...

Endpoint Manager Mobile Confirmed In CISA 01 Jun 2026
CVE-2026-1340

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Endpoint Manager Mobile Confirmed In CISA 01 Jun 2026
CVE-2026-1603

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored...

Endpoint Manager Confirmed In CISA 01 Jun 2026
CVE-2026-1281

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Endpoint Manager Mobile Confirmed In CISA 01 Jun 2026
CVE-2023-32563

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

Avalanche High Beyond CISA 05 Jun 2025
CVE-2025-4428

Remote Code Execution

Endpoint Manager Mobile Confirmed In CISA 21 May 2025
CVE-2025-4427

Authentication Bypass

Endpoint Manager Mobile Confirmed In CISA 21 May 2025
CVE-2024-22024

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA...

ICS, IPS Confirmed Beyond CISA 28 Apr 2025
CVE-2023-35078

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application...

Endpoint Manager Mobile Confirmed In CISA 25 Jul 2023
CVE-2023-35081

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an...

EPMM Confirmed In CISA 31 Jul 2023
CVE-2023-38035

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass...

MobileIron Sentry Confirmed In CISA 22 Aug 2023
CVE-2024-21887

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an...

ICS, IPS Confirmed In CISA 10 Jan 2024
CVE-2023-46805

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access...

ICS, IPS Confirmed In CISA 10 Jan 2024
CVE-2023-35082

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of...

EPMM Confirmed In CISA 18 Jan 2024
CVE-2024-21893

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and...

ICS, IPS Confirmed In CISA 31 Jan 2024
CVE-2021-44529

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with...

Ivanti EPM Confirmed In CISA 25 Mar 2024
CVE-2024-8190

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker...

CSA (Cloud Services Appliance) Confirmed In CISA 13 Sep 2024
CVE-2024-8963

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

CSA (Cloud Services Appliance) Confirmed In CISA 19 Sep 2024
CVE-2024-7593

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker...

vTM Confirmed In CISA 24 Sep 2024
CVE-2024-29824

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same...

EPM Confirmed In CISA 02 Oct 2024
CVE-2024-9379

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run...

CSA (Cloud Services Appliance) Confirmed In CISA 09 Oct 2024
CVE-2024-9380

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin...

CSA (Cloud Services Appliance) Confirmed In CISA 09 Oct 2024
CVE-2025-0282

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons...

Connect Secure, Policy Secure, Neurons for ZTA gateways Confirmed In CISA 08 Jan 2025
CVE-2024-13159

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote...

Endpoint Manager Confirmed In CISA 10 Mar 2025
CVE-2024-13160

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote...

Endpoint Manager Confirmed In CISA 10 Mar 2025
CVE-2024-13161

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote...

Endpoint Manager Confirmed In CISA 10 Mar 2025
CVE-2025-22457

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA...

Connect Secure, Policy Secure, Neurons for ZTA gateways Confirmed In CISA 04 Apr 2025

Showing 30 of 30 Ivanti known exploited vulnerabilities.

Recurring weakness patterns

Authentication, control, and limitation account for twelve mapped occurrences across this Ivanti KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.