Product of Ivanti

Endpoint Manager (EPM)

As of , 5 Ivanti Endpoint Manager (EPM) vulnerabilities are on CISA's list of exploited vulnerabilities; 1 was added in 2026. Patch first: CVE-2024-29824.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2024-29824SQL InjectionIvanti Endpoint Manager (EPM)Patch this weekMetasploit module; EPSS 0.990.99
2CVE-2026-1603Authentication BypassIvanti Endpoint Manager (EPM)Patch this weekEPSS 0.880.88
3CVE-2024-13159Absolute Path TraversalIvanti Endpoint Manager (EPM)Patch this weekEPSS 0.990.99
4CVE-2024-13160Absolute Path TraversalIvanti Endpoint Manager (EPM)Patch this weekEPSS 0.910.91
5CVE-2024-13161Absolute Path TraversalIvanti Endpoint Manager (EPM)Patch this weekEPSS 0.900.90

Added each year

1232024: 1120242025: 3320252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20241
20253
20261

Used in ransomware