Ivanti develops a focused line of enterprise mobility, endpoint management, and secure remote access platforms that occupy critical positions in corporate IT infrastructure and are widely deployed across business networks. Despite its concentrated product portfolio—anchored by Connect Secure, Avalanche, Endpoint Manager, Policy Secure, and Endpoint Manager Mobile—the vendor carries a large vulnerability footprint and ranks among the most prominent in the landscape, reflecting the complexity and attack surface inherent to these privileged management and access-control systems. Vulnerabilities affecting Ivanti skew toward serious outcomes and have a moderate tendency toward both confirmed in-the-wild exploitation and public exploit availability, consistent with the high value of compromising endpoint and access-control infrastructure. The exposure recurs through SQL injection, path traversal, out-of-bounds write, and cross-site scripting weaknesses, reflecting the web-facing and data-handling demands of remote access and management appliances. Defenders should prioritize inventory and patching of these products, particularly internet-reachable instances; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ivanti over time
Of all the CVEs published by Ivanti as a CNA, 96.9% affect products that Ivanti develops as a vendor.
Of all the CVEs published that affect products developed by Ivanti, 37.9% are self-published by Ivanti as a CNA.
Signals from CVEs in this vendor scope (494 CVEs).
494 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-10520CRITICAL An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execu | Jun 9, 2026 | 10.0 | 99 | YES | YES |
CVE-2025-22457CRITICAL A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows | Apr 3, 2025 | 9.8 | 99 | YES | YES |
CVE-2021-44529CRITICAL A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). | Dec 8, 2021 | 9.8 | 99 | YES | YES |
CVE-2019-11510CRITICAL In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to p | May 8, 2019 | 10.0 | 99 | YES | YES |
CVE-2026-1340CRITICAL A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | Jan 29, 2026 | 9.8 | 98 | YES | YES |
CVE-2025-4427HIGH An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources without proper credentials via the | May 13, 2025 | 7.5 | 98 | YES | YES |
CVE-2025-0282CRITICAL A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22. | Jan 8, 2025 | 9.0 | 98 | YES | YES |
CVE-2024-8963CRITICAL Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. | Sep 19, 2024 | 9.1 | 98 | YES | YES |
CVE-2024-7593CRITICAL Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the | Aug 13, 2024 | 9.8 | 98 | YES | YES |
CVE-2024-29824HIGH An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | May 31, 2024 | 8.8 | 98 | YES | YES |
Signals from CVEs in this vendor scope (494 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ivanti.
Media articles that mention a CVE ID that affects a product developed by Ivanti — matched by CVE ID, not by vendor name.