Vendor

Ivanti, page 2

As of , 35 Ivanti vulnerabilities are on CISA's list of exploited vulnerabilities, 12 of them used in ransomware campaigns; 5 were added in 2026. Patch first: CVE-2019-11539.

#VulnerabilityProductOur groupListedDeadlineEPSS
26CVE-2023-35082Authentication BypassIvanti Endpoint Manager Mobile (EPMM) and MobileIron CorePatch this weekRansomware use; EPSS 0.990.99
27CVE-2023-35081Path TraversalIvanti Endpoint Manager Mobile (EPMM)Patch this weekEPSS 0.640.64
28CVE-2023-35078Endpoint Manager Mobile Authentication BypassIvanti Endpoint Manager Mobile (EPMM)Patch this weekRansomware use; EPSS 0.990.99
29CVE-2020-8243Code ExecutionIvanti Pulse Connect SecurePatch this weekEPSS 0.910.91
30CVE-2021-22893Use-After-FreeIvanti Pulse Connect SecurePatch this weekRansomware use0.47
31CVE-2024-9379SQL InjectionIvanti Cloud Services Appliance (CSA)Patch soon0.44
32CVE-2021-22894Collaboration Suite Buffer OverflowIvanti Pulse Connect SecurePatch soon0.41
33CVE-2021-22899Command InjectionIvanti Pulse Connect SecurePatch soon0.23
34CVE-2021-22900Unrestricted File UploadIvanti Pulse Connect SecurePatch soon0.14
35CVE-2026-6973Improper Input ValidationIvanti Endpoint Manager Mobile (EPMM)Patch soon0.03