Ivanti Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Ivanti products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

30

In CISA KEV

26

Beyond CISA KEV

4

Sensor Observed

3

Virtual Patch Available

1

Ivanti KEVs Added by Year

Loading...

30 Ivanti KEVs added all time (primary attestation date).

CVE Confidence CISA KEV Added
CVE-2026-10520

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to...

Confirmed In CISA 10 Jun 2026
CVE-2024-38653

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

High Not in CISA 05 Sep 2025
CVE-2021-30497

Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath...

High Not in CISA 16 Jul 2025
CVE-2026-6973

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user...

Confirmed In CISA 01 Jun 2026
CVE-2026-1340

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Confirmed In CISA 01 Jun 2026
CVE-2026-1603

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored...

Confirmed In CISA 01 Jun 2026
CVE-2026-1281

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Confirmed In CISA 01 Jun 2026
CVE-2023-32563

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

High Not in CISA 05 Jun 2025
CVE-2025-4428

Remote Code Execution

Confirmed In CISA 21 May 2025
CVE-2025-4427

Authentication Bypass

Confirmed In CISA 21 May 2025
CVE-2024-22024

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA...

Confirmed Not in CISA 28 Apr 2025
CVE-2023-35078

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application...

Confirmed In CISA 25 Jul 2023
CVE-2023-35081

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an...

Confirmed In CISA 31 Jul 2023
CVE-2023-38035

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass...

Confirmed In CISA 22 Aug 2023
CVE-2024-21887

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an...

Confirmed In CISA 10 Jan 2024
CVE-2023-46805

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access...

Confirmed In CISA 10 Jan 2024
CVE-2023-35082

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of...

Confirmed In CISA 18 Jan 2024
CVE-2024-21893

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and...

Confirmed In CISA 31 Jan 2024
CVE-2021-44529

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with...

Confirmed In CISA 25 Mar 2024
CVE-2024-8190

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker...

Confirmed In CISA 13 Sep 2024
CVE-2024-8963

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

Confirmed In CISA 19 Sep 2024
CVE-2024-7593

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker...

Confirmed In CISA 24 Sep 2024
CVE-2024-29824

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same...

Confirmed In CISA 02 Oct 2024
CVE-2024-9379

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run...

Confirmed In CISA 09 Oct 2024
CVE-2024-9380

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin...

Confirmed In CISA 09 Oct 2024

Common Vulnerability Classes (CWE)

  • CWE-287 — Improper Authentication 4
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 4
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
  • CWE-36 — Absolute Path Traversal 3
  • CWE-288 — Authentication Bypass Using an Alternate Path or Channel 2
  • CWE-121 — Stack-based Buffer Overflow 2
  • CWE-611 — Improper Restriction of XML External Entity Reference 2
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 2

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology