Vendor
Ivanti, page 2
As of , 35 Ivanti vulnerabilities are on CISA's list of exploited vulnerabilities, 12 of them used in ransomware campaigns; 5 were added in 2026. Patch first: CVE-2019-11539.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 26 | CVE-2023-35082Authentication Bypass | Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 27 | CVE-2023-35081Path Traversal | Ivanti Endpoint Manager Mobile (EPMM) | Patch this weekEPSS 0.64 | 0.64 | ||
| 28 | CVE-2023-35078Endpoint Manager Mobile Authentication Bypass | Ivanti Endpoint Manager Mobile (EPMM) | Patch this weekRansomware use; EPSS 0.99 | 0.99 | ||
| 29 | CVE-2020-8243Code Execution | Ivanti Pulse Connect Secure | Patch this weekEPSS 0.91 | 0.91 | ||
| 30 | CVE-2021-22893Use-After-Free | Ivanti Pulse Connect Secure | Patch this weekRansomware use | 0.47 | ||
| 31 | CVE-2024-9379SQL Injection | Ivanti Cloud Services Appliance (CSA) | Patch soon | 0.44 | ||
| 32 | CVE-2021-22894Collaboration Suite Buffer Overflow | Ivanti Pulse Connect Secure | Patch soon | 0.41 | ||
| 33 | CVE-2021-22899Command Injection | Ivanti Pulse Connect Secure | Patch soon | 0.23 | ||
| 34 | CVE-2021-22900Unrestricted File Upload | Ivanti Pulse Connect Secure | Patch soon | 0.14 | ||
| 35 | CVE-2026-6973Improper Input Validation | Ivanti Endpoint Manager Mobile (EPMM) | Patch soon | 0.03 |