Product of Ivanti

Cloud Services Appliance (CSA)

As of , 3 Ivanti Cloud Services Appliance (CSA) vulnerabilities are on CISA's list of exploited vulnerabilities; 0 were added in 2026. Patch first: CVE-2024-9380.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2024-9380OS Command InjectionIvanti Cloud Services Appliance (CSA)Patch this weekEPSS 0.600.60
2CVE-2024-8963Path TraversalIvanti Cloud Services Appliance (CSA)Patch this weekEPSS 0.990.99
3CVE-2024-9379SQL InjectionIvanti Cloud Services Appliance (CSA)Patch soon0.44

Added each year

1232024: 3320242025: nonenone20252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20243
2025none
2026none

Used in ransomware