← Back to News Iceland Security Dashboard Browse all tags
ivanti

Ivanti

pulse-connect-secure 7pulse connect secure 7endpoint manager mobile (epmm) 7endpoint-manager-mobile 6endpoint-manager 5endpoint_manager_mobile 4endpoint manager (epm) 4cloud-services-appliance 4secure_access_client 3connect-secure 3cloud services appliance (csa) 3epmm 2endpoint_manager 2connect secure, policy secure, and zta gateways 2connect secure and policy secure 2xtraction 1vtm 1virtual_traffic_manager 1virtual traffic manager 1sentry 1

CVEs tagged with this vendor (47)

CVE-2026-1281 🚨 CVSS 9.8 Endpoint Manager Mobile (EPMM)
CVE-2026-1281 is a critical code injection vulnerability in Ivanti Endpoint Manager Mobile that allows unauthenticated remote code execution. The vulnerability …
CVE-2026-1340 🚨 CVSS 9.8 Endpoint Manager Mobile (EPMM)
CVE-2026-1340 is a critical code injection vulnerability (CWE-94) in Ivanti Endpoint Manager Mobile that allows unauthenticated remote code execution. The vulne…
CVE-2026-1603 🚨 CVSS 8.6 Endpoint Manager (EPM)
CVE-2026-1603 is a high-severity authentication bypass vulnerability in Ivanti Endpoint Manager versions prior to 2024 SU5, allowing remote unauthenticated atta…
CVE-2026-6973 🚨 CVSS 7.2 Endpoint Manager Mobile (EPMM)
CVE-2026-6973 is a high-severity (CVSS 7.2) remote code execution vulnerability in Ivanti EPMM versions prior to 12.6.1.1, 12.7.0.1, and 12.8.0.1, caused by imp…
CVE-2019-11510 🚨 Pulse Connect Secure
CVE-2019-11510 is a critical path traversal vulnerability affecting Pulse Secure Pulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 …
CVE-2019-11539 🚨 Pulse Connect Secure and Pulse Policy Secure
CVE-2019-11539 is a command injection vulnerability in Ivanti Pulse Connect Secure and Pulse Policy Secure versions 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, …
CVE-2020-15505 🚨 MobileIron Multiple Products
CVE-2020-15505 is a critical remote code execution vulnerability affecting Ivanti MobileIron Core, Connector, Sentry, and Monitor and Reporting Database version…
CVE-2020-8243 🚨 Pulse Connect Secure
CVE-2020-8243 is a high-severity vulnerability in Ivanti Pulse Connect Secure versions prior to 9.1R8.2 that allows authenticated attackers to upload custom tem…
CVE-2020-8260 🚨 Pulse Connect Secure
CVE-2020-8260 is a high-severity vulnerability in Ivanti Pulse Connect Secure versions prior to 9.1R9 that allows authenticated attackers to execute arbitrary c…
CVE-2021-22893 🚨 Pulse Connect Secure
CVE-2021-22893 is a critical authentication bypass vulnerability in Ivanti Pulse Connect Secure versions 9.0R3, 9.1R1, and higher, affecting the Windows File Sh…
CVE-2021-22894 🚨 Pulse Connect Secure
CVE-2021-22894 is a high-severity buffer overflow vulnerability in Ivanti Pulse Connect Secure versions prior to 9.1R11.4, allowing remote authenticated attacke…
CVE-2021-22899 🚨 Pulse Connect Secure
CVE-2021-22899 is a command injection vulnerability (CWE-77) in Ivanti Pulse Connect Secure versions prior to 9.1R11.4, allowing remote authenticated attackers …
CVE-2021-22900 🚨 Pulse Connect Secure
CVE-2021-22900 is a HIGH severity vulnerability (CVSS 7.2) in Ivanti Pulse Connect Secure versions prior to 9.1R11.4, allowing authenticated administrators to p…
CVE-2021-44529 🚨 Endpoint Manager Cloud Service Appliance (EPM CSA)
CVE-2021-44529 is a critical code injection vulnerability in the Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) that allows unauthenticated users to …
CVE-2023-35078 🚨 Endpoint Manager Mobile (EPMM)
CVE-2023-35078 is a critical authentication bypass vulnerability (CWE-287) in Ivanti Endpoint Manager Mobile (EPMM) that allows unauthorized users to access res…
CVE-2023-35081 🚨 Endpoint Manager Mobile (EPMM)
CVE-2023-35081 is a path traversal vulnerability (CWE-22) in Ivanti Endpoint Manager Mobile (EPMM) versions 11.10.x prior to 11.10.0.3, 11.9.x prior to 11.9.1.2…
CVE-2023-35082 🚨 Endpoint Manager Mobile (EPMM) and MobileIron Core
CVE-2023-35082 is a critical authentication bypass vulnerability (CWE-287) affecting Ivanti EPMM versions 11.10 and older, allowing unauthorized access to restr…
CVE-2023-38035 🚨 Sentry
CVE-2023-38035 is a critical authentication bypass vulnerability in Ivanti MobileIron Sentry versions 9.18.0 and below, caused by an insufficiently restrictive …
CVE-2023-46805 🚨 Connect Secure and Policy Secure
CVE-2023-46805 is a HIGH severity authentication bypass vulnerability (CVSS 8.2) affecting Ivanti ICS 9.x, 22.x, and Ivanti Policy Secure web components. It all…
CVE-2024-13159 🚨 Endpoint Manager (EPM)
CVE-2024-13159 is a critical path traversal vulnerability in Ivanti Endpoint Manager (EPM) versions prior to the 2024 January-2025 Security Update and 2022 SU6 …
CVE-2024-13160 🚨 Endpoint Manager (EPM)
CVE-2024-13160 is a critical path traversal vulnerability (CWE-36) in Ivanti Endpoint Manager (EPM) affecting versions prior to the 2024 January-2025 Security U…
CVE-2024-13161 🚨 Endpoint Manager (EPM)
CVE-2024-13161 is a critical path traversal vulnerability in Ivanti Endpoint Manager (EPM) versions prior to the 2024 January-2025 Security Update and 2022 SU6 …
CVE-2024-21887 🚨 Connect Secure and Policy Secure
CVE-2024-21887 is a critical command injection vulnerability (CWE-77) affecting Ivanti Connect Secure and Ivanti Policy Secure versions 9.x and 22.x. It allows …
CVE-2024-21893 🚨 Connect Secure, Policy Secure, and Neurons
CVE-2024-21893 is a server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure, Policy Secure, and Neurons for ZTA versions 9.x an…
CVE-2024-29824 🚨 Endpoint Manager (EPM)
CVE-2024-29824 is a critical SQL injection vulnerability in the Core server of Ivanti Endpoint Manager (EPM) 2022 SU5 and prior versions. It allows an unauthent…
CVE-2024-7593 🚨 Virtual Traffic Manager
CVE-2024-7593 is a critical authentication bypass vulnerability in Ivanti vTM affecting versions other than 22.2R1 and 22.7R2, allowing remote unauthenticated a…
CVE-2024-8190 🚨 Cloud Services Appliance
CVE-2024-8190 is a command injection vulnerability (CWE-78) in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and earlier, allowing remote authenticated…
CVE-2024-8963 🚨 Cloud Services Appliance (CSA)
CVE-2024-8963 is a critical path traversal vulnerability (CWE-22) in Ivanti Cloud Services Appliance (CSA) versions prior to 4.6 Patch 519, allowing remote unau…
CVE-2024-9379 🚨 Cloud Services Appliance (CSA)
CVE-2024-9379 is a SQL injection vulnerability (CWE-89) in the admin web console of Ivanti Cloud Services Appliance (CSA) versions prior to 5.0.2. It allows a r…
CVE-2024-9380 🚨 Cloud Services Appliance (CSA)
CVE-2024-9380 is a high-severity command injection vulnerability (CVSS 7.2) in the admin web console of Ivanti Cloud Services Appliance (CSA) versions prior to …
CVE-2025-0282 🚨 Connect Secure, Policy Secure, and ZTA Gateways
CVE-2025-0282 is a critical stack-based buffer overflow vulnerability affecting Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways prior to spec…
CVE-2025-22457 🚨 Connect Secure, Policy Secure, and ZTA Gateways
CVE-2025-22457 is a critical stack-based buffer overflow vulnerability affecting Ivanti Connect Secure, Policy Secure, and ZTA Gateways prior to specific 22.7/2…
CVE-2025-4427 🚨 Endpoint Manager Mobile (EPMM)
CVE-2025-4427 is a medium severity (CVSS 5.3) authentication bypass vulnerability in the API component of Ivanti Endpoint Manager Mobile versions 12.5.0.0 and p…
CVE-2025-4428 🚨 Endpoint Manager Mobile (EPMM)
CVE-2025-4428 is a high-severity remote code execution vulnerability in the API component of Ivanti Endpoint Manager Mobile versions 12.5.0.0 and prior. It is c…
CVE-2026-8043 CVSS 9.6 xtraction
CVE-2026-5787 CVSS 8.9 endpoint_manager_mobile
CVE-2026-5786 CVSS 8.8 endpoint_manager_mobile
CVE-2026-8111 CVSS 8.8 endpoint_manager
CVE-2026-8992 CVSS 8.8 secure_access_client
No NVD or KEV data was available for CVE-2026-8992. Consequently, specific technical details regarding the vulnerability's nature, affected components, and seve…
CVE-2026-9614 CVSS 8.8
CVE-2026-9614 is a high-severity improper access control vulnerability (CWE-284) in Ivanti Neurons for ITSM affecting both cloud and on-premises deployments. It…
CVE-2026-3483 CVSS 7.8 desktop_\&_server_management
CVE-2026-7432 CVSS 7.8 secure_access_client
CVE-2026-7821 CVSS 7.4 endpoint_manager_mobile
CVE-2026-8051 CVSS 7.2 virtual_traffic_manager
CVE-2026-5788 CVSS 7.0 endpoint_manager_mobile
CVE-2026-1602 CVSS 6.5 endpoint_manager
CVE-2026-7431 CVSS 4.4 secure_access_client

Articles tagged with Ivanti (30)

HIGH
[NEU] [hoch] Ivanti Neurons for ITSM: Schwachstelle ermöglicht Privilegieneskalation
BSI Germany · 2026-06-02
HIGH
Vulnérabilité dans les produits Ivanti (02 juin 2026)
CERT-FR (ANSSI) · 2026-06-02
HIGH
NCSC-2026-0160 [1.00] [M/H] Kwetsbaarheden verholpen in Ivanti Endpoint Manager
NCSC Netherlands · 2026-05-15
CRITICAL
Fortinet, Ivanti Patch Critical Vulnerabilities
SecurityWeek · 2026-05-13
CRITICAL
Federal agencies ordered to patch Ivanti EPMM zero-day in 3 days
SC Media · 2026-05-08
CRITICAL
Ivanti customers confront yet another actively exploited zero-day
CyberScoop · 2026-05-07
CRITICAL
Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
The Hacker News · 2026-05-07
HIGH
NCSC-2026-0135 [1.00] [H/H] Kwetsbaarheden verholpen in Ivanti Endpoint Manager Mobile
NCSC Netherlands · 2026-05-07
CRITICAL
Ivanti warns of new EPMM flaw exploited in zero-day attacks
BleepingComputer · 2026-05-07
CRITICAL
CISA Adds One Known Exploited Vulnerability to Catalog
CISA All Advisories · 2026-05-07
CRITICAL
Multiples vulnérabilités dans Ivanti Endpoint Manager Mobile (07 mai 2026)
CERT-FR (ANSSI) · 2026-05-07
MEDIUM
Two Vulnerabilities Patched in Ivanti Neurons for ITSM
SecurityWeek · 2026-04-15
CRITICAL
Ivanti Connect Secure Zero-Day Vulnerability
FortiGuard Threat Signal · 2026-03-13
HIGH
Fake enterprise VPN downloads used to steal company credentials
BleepingComputer · 2026-03-13
CRITICAL
CISA warns of actively exploited Ivanti EPM and Cisco SD-WAN flaws
CSO Online · 2026-03-11
HIGH
Fortinet, Ivanti, Intel Patch High-Severity Vulnerabilities
SecurityWeek · 2026-03-11
HIGH
[NEU] [mittel] Ivanti Desktop and Server Management: Schwachstelle ermöglicht Privilegieneskalation
BSI Germany · 2026-03-11
MEDIUM
Vulnérabilité dans Ivanti Desktop and Server Management (DSM) (11 mars 2026)
CERT-FR (ANSSI) · 2026-03-11
CRITICAL
CISA Flags SolarWinds, Ivanti, and Workspace One Vulnerabilities as Actively Exploited
The Hacker News · 2026-03-10
CRITICAL
CISA warns that RESURGE malware can be dormant on Ivanti devices
BleepingComputer · 2026-02-27
CRITICAL
Attackers exploit Ivanti EPMM zero-days to seize control of MDM servers
CSO Online · 2026-02-23
CRITICAL
Ivanti Exploitation Surges as Zero-Day Attacks Traced Back to July 2025
SecurityWeek · 2026-02-19
CRITICAL
Critical Vulnerabilities in Ivanti EPMM Exploited
Unit 42 · 2026-02-17
CRITICAL
One threat actor responsible for 83% of recent Ivanti RCE attacks
BleepingComputer · 2026-02-14
INFO
Attackers are moving at machine speed, defenders are still in meetings
Help Net Security · 2026-02-13
CRITICAL
Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy — Again
Dark Reading · 2026-02-12
CRITICAL
83% of Ivanti EPMM Exploits Linked to Single IP on Bulletproof Hosting Infrastructure
The Hacker News · 2026-02-12
CRITICAL
Ivanti EPMM exploitation: Researchers warn of “sleeper” webshells
Help Net Security · 2026-02-11
HIGH
Ivanti Patches Endpoint Manager Vulnerabilities Disclosed in October 2025
SecurityWeek · 2026-02-11
HIGH
[NEU] [hoch] Ivanti Endpoint Manager: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen
BSI Germany · 2026-02-11