Ivant Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Ivant products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
30
In CISA KEV
26
Beyond CISA KEV
4
Sensor Observed
3
Virtual Patch Available
1
Ivant KEVs Added by Year
30 Ivant KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2026-10520
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to... |
Sentry | Confirmed | In CISA | 10 Jun 2026 |
|
CVE-2024-38653
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server. |
Avalanche | High | Not in CISA | 05 Sep 2025 |
|
CVE-2021-30497
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath... |
Avalanche | High | Not in CISA | 16 Jul 2025 |
|
CVE-2026-6973
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user... |
Endpoint Manager Mobile | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2026-1340
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. |
Endpoint Manager Mobile | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2026-1603
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored... |
Endpoint Manager | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2026-1281
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. |
Endpoint Manager Mobile | Confirmed | In CISA | 01 Jun 2026 |
|
CVE-2023-32563
An unauthenticated attacker could achieve the code execution through a RemoteControl server. |
Avalanche | High | Not in CISA | 05 Jun 2025 |
|
CVE-2025-4428
Remote Code Execution |
Endpoint Manager Mobile | Confirmed | In CISA | 21 May 2025 |
|
CVE-2025-4427
Authentication Bypass |
Endpoint Manager Mobile | Confirmed | In CISA | 21 May 2025 |
|
CVE-2024-22024
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA... |
ICS, IPS | Confirmed | Not in CISA | 28 Apr 2025 |
|
CVE-2023-35078
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application... |
Endpoint Manager Mobile | Confirmed | In CISA | 25 Jul 2023 |
|
CVE-2023-35081
A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an... |
EPMM | Confirmed | In CISA | 31 Jul 2023 |
|
CVE-2023-38035
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass... |
MobileIron Sentry | Confirmed | In CISA | 22 Aug 2023 |
|
CVE-2024-21887
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an... |
ICS, IPS | Confirmed | In CISA | 10 Jan 2024 |
|
CVE-2023-46805
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access... |
ICS, IPS | Confirmed | In CISA | 10 Jan 2024 |
|
CVE-2023-35082
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of... |
EPMM | Confirmed | In CISA | 18 Jan 2024 |
|
CVE-2024-21893
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and... |
ICS, IPS | Confirmed | In CISA | 31 Jan 2024 |
|
CVE-2021-44529
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with... |
Ivanti EPM | Confirmed | In CISA | 25 Mar 2024 |
|
CVE-2024-8190
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker... |
CSA (Cloud Services Appliance) | Confirmed | In CISA | 13 Sep 2024 |
|
CVE-2024-8963
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. |
CSA (Cloud Services Appliance) | Confirmed | In CISA | 19 Sep 2024 |
|
CVE-2024-7593
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker... |
vTM | Confirmed | In CISA | 24 Sep 2024 |
|
CVE-2024-29824
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same... |
EPM | Confirmed | In CISA | 02 Oct 2024 |
|
CVE-2024-9379
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run... |
CSA (Cloud Services Appliance) | Confirmed | In CISA | 09 Oct 2024 |
|
CVE-2024-9380
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin... |
CSA (Cloud Services Appliance) | Confirmed | In CISA | 09 Oct 2024 |
Common Vulnerability Classes (CWE)
- CWE-287 — Improper Authentication 4
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 4
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
- CWE-36 — Absolute Path Traversal 3
- CWE-288 — Authentication Bypass Using an Alternate Path or Channel 2
- CWE-121 — Stack-based Buffer Overflow 2
- CWE-611 — Improper Restriction of XML External Entity Reference 2
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 2
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology