Vendor

Ivanti

As of , 35 Ivanti vulnerabilities are on CISA's list of exploited vulnerabilities, 12 of them used in ransomware campaigns; 5 were added in 2026. Patch first: CVE-2019-11539.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2019-11539Pulse Connect Secure and Policy Secure Command InjectionIvanti Pulse Connect Secure and Pulse Policy SecurePatch this weekRansomware use; Metasploit module; EPSS 0.99; verified Exploit-DB entry0.99
2CVE-2026-1340Code InjectionIvanti Endpoint Manager Mobile (EPMM)Patch this weekMetasploit module; EPSS 0.990.99
3CVE-2026-1281Code InjectionIvanti Endpoint Manager Mobile (EPMM)Patch this weekMetasploit module; EPSS 0.990.99
4CVE-2025-4427Authentication BypassIvanti Endpoint Manager Mobile (EPMM)Patch this weekMetasploit module; EPSS 0.990.99
5CVE-2025-4428Code InjectionIvanti Endpoint Manager Mobile (EPMM)Patch this weekMetasploit module; EPSS 0.870.87
6CVE-2025-22457Stack-Based Buffer OverflowIvanti Connect Secure, Policy Secure, and ZTA GatewaysPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
7CVE-2024-29824SQL InjectionIvanti Endpoint Manager (EPM)Patch this weekMetasploit module; EPSS 0.990.99
8CVE-2024-7593Authentication BypassIvanti Virtual Traffic ManagerPatch this weekMetasploit module; EPSS 0.990.99
9CVE-2021-44529Code InjectionIvanti Endpoint Manager Cloud Service Appliance (EPM CSA)Patch this weekRansomware use; Metasploit module; EPSS 0.990.99
10CVE-2024-21893Server-Side Request Forgery (SSRF)Ivanti Connect Secure, Policy Secure, and NeuronsPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
11CVE-2023-46805Authentication BypassIvanti Connect Secure and Policy SecurePatch this weekRansomware use; Metasploit module; EPSS 0.990.99
12CVE-2024-21887Command InjectionIvanti Connect Secure and Policy SecurePatch this weekRansomware use; Metasploit module; EPSS 0.990.99
13CVE-2023-38035Authentication BypassIvanti SentryPatch this weekRansomware use; Metasploit module; EPSS 0.990.99
14CVE-2019-11510Arbitrary File ReadIvanti Pulse Connect SecurePatch this weekRansomware use; Metasploit module; EPSS 0.990.99
15CVE-2020-8260Code ExecutionIvanti Pulse Connect SecurePatch this weekMetasploit module; EPSS 0.960.96
16CVE-2020-15505Remote Code ExecutionIvanti MobileIron Multiple ProductsPatch this weekMetasploit module; EPSS 0.990.99
17CVE-2026-10520OS Command InjectionIvanti SentryPatch this weekEPSS 0.990.99
18CVE-2026-1603Authentication BypassIvanti Endpoint Manager (EPM)Patch this weekEPSS 0.880.88
19CVE-2024-13159Absolute Path TraversalIvanti Endpoint Manager (EPM)Patch this weekEPSS 0.990.99
20CVE-2024-13160Absolute Path TraversalIvanti Endpoint Manager (EPM)Patch this weekEPSS 0.910.91
21CVE-2024-13161Absolute Path TraversalIvanti Endpoint Manager (EPM)Patch this weekEPSS 0.900.90
22CVE-2025-0282Stack-Based Buffer OverflowIvanti Connect Secure, Policy Secure, and ZTA GatewaysPatch this weekRansomware use; EPSS 0.990.99
23CVE-2024-9380OS Command InjectionIvanti Cloud Services Appliance (CSA)Patch this weekEPSS 0.600.60
24CVE-2024-8963Path TraversalIvanti Cloud Services Appliance (CSA)Patch this weekEPSS 0.990.99
25CVE-2024-8190OS Command InjectionIvanti Cloud Services AppliancePatch this weekEPSS 0.890.89

The next 10, from number 26

Products

  • Endpoint Manager Mobile (EPMM)7 entries
  • Pulse Connect Secure7 entries
  • Endpoint Manager (EPM)5 entries
  • Cloud Services Appliance (CSA)3 entries
  • Connect Secure and Policy Secure2 entries
  • Connect Secure, Policy Secure, and ZTA Gateways2 entries
  • Sentry2 entries
  • Cloud Services Appliance1 entry
  • Connect Secure, Policy Secure, and Neurons1 entry
  • Endpoint Manager Cloud Service Appliance (EPM CSA)1 entry
  • Endpoint Manager Mobile (EPMM) and MobileIron Core1 entry
  • MobileIron Multiple Products1 entry
  • Pulse Connect Secure and Pulse Policy Secure1 entry
  • Virtual Traffic Manager1 entry

Added each year

510152021: 9920212022: nonenone20222023: 3320232024: 111120242025: 7720252026: 552026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20219
2022none
20233
202411
20257
20265

Used in ransomware

Changes CISA made to these entries

  1. CVE-2026-10520 Ivanti SentryEdited: description.
  2. CVE-2026-1281 Ivanti Endpoint Manager Mobile (EPMM)Removed from CISA's list.
  3. CVE-2026-1281 Ivanti Endpoint Manager Mobile (EPMM)Restored to CISA's list.
  4. CVE-2021-22900 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  5. CVE-2021-22899 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  6. CVE-2021-22894 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  7. CVE-2021-22893 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  8. CVE-2020-8260 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  9. CVE-2020-8243 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.
  10. CVE-2019-11510 Ivanti Pulse Connect SecureDeadline moved from 23 April 2021 to 3 May 2022.

Every change we recorded