VulnSea

ivanti has 18 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 10 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 10. The median CVSS is 9.4 (critical), with 12 rated critical. 44% have been exploited in the wild — well above the 1% corpus average, so ivanti flaws are worth patching on sight. When CISA adds a ivanti CVE to KEV it happens fast: a median of 1 day after publication (6 cases). The dominant weakness classes are CWE-502 (5) and CWE-862 (4). Most affected products: neurons_for_itsm (8), connect_secure (6), endpoint_manager_mobile (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
44% vs 1% corpus
Median CVSS
9.4
Publish → KEV
1 d median(6)
Last 90 days
10 prev 0

Products

  • neurons_for_itsm 8
  • connect_secure 6
  • endpoint_manager_mobile 2
  • Sentry 1
  • endpoint_manager_cloud_services_appliance 1
18
Total CVEs
12
Critical
8
CISA KEV
8
Exploited

ivanti vulnerabilities

CVEs affecting ivanti, newest first. Open any entry for full detail, references, and exploit status.

18 CVEsRSS

CVE-2026-83527High· 8.1
2w ago

An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.

An Authentication Bypass vulnerability in Sentry before R10.8.2, R10.7.3 and R10.6.4 allows a remote unauthenticated attacker to gain administrative level access.

TwilightIvanti · SentryEPSS 1.5%via NVD
CVE-2026-18851High· 8.8
2w ago

Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.

Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin.

Twilightivanti · endpoint_manager_mobileEPSS 1.0%via NVD
CVE-2026-12745Critical· 9.8
2w ago

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

Midnightivanti · neurons_for_itsmEPSS 2.1%via NVD
CVE-2026-12744Critical· 9.8
2w ago

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server.

Midnightivanti · neurons_for_itsmEPSS 2.2%via NVD
CVE-2026-12651High· 8.8
2w ago

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Twilightivanti · neurons_for_itsmEPSS 1.5%via NVD
CVE-2026-12650Critical· 9.9
2w ago

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Midnightivanti · neurons_for_itsmEPSS 1.5%via NVD
CVE-2026-12648High· 8.8
2w ago

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Twilightivanti · neurons_for_itsmEPSS 1.5%via NVD
CVE-2026-12647Critical· 9.9
2w ago

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Midnightivanti · neurons_for_itsmEPSS 1.2%via NVD
CVE-2026-12646Critical· 9.9
2w ago

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Midnightivanti · neurons_for_itsmEPSS 1.2%via NVD
CVE-2026-12645Critical· 9.9
2w ago

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server.

Midnightivanti · neurons_for_itsmEPSS 1.2%via NVD
CVE-2025-22457Critical· 9.0CISA KEV0dayPoC
1y ago

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code…

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code…

Hadalivanti · connect_secureEPSS 100%via NVD
CVE-2025-0282Critical· 9.0CISA KEV0dayPoC
1y ago

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve…

Hadalivanti · connect_secureEPSS 100%via NVD
CVE-2024-21893High· 8.2CISA KEV0dayPoC
2y ago

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without auth…

Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2024-21887Critical· 9.1CISA KEV0dayPoC
2y ago

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the…

Hadalivanti · connect_secureEPSS 100%via NVD
CVE-2023-46805High· 8.2CISA KEV0dayPoC
2y ago

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

Abyssalivanti · connect_secureEPSS 100%via NVD
CVE-2023-35078Critical· 9.8CISA KEV0dayPoC
3y ago

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

Hadalivanti · endpoint_manager_mobileEPSS 100%via NVD
CVE-2021-44529Critical· 9.8CISA KEVPoC
4y ago

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

Hadalivanti · endpoint_manager_cloud_services_applianceEPSS 99%via NVD
CVE-2021-22893Critical· 10.0CISA KEVPoC
5y ago

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticat…

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticat…

Hadalivanti · connect_secureEPSS 47%via NVD
ivanti vulnerabilities (CVEs) · VulnSea