Exploited CVEs / By vendor / Ivanti

Ivanti vulnerabilities actively exploited

35 Ivanti CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.

Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2026-10520 (Sentry, added 2026-06-11). 12 of the 35 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.

35 exploited CVEs12 ransomware-linked
Senserva AI Opinion and rich prompt for Ivanti exploited CVEs

Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.

Endpoint Manager Mobile (EPMM): 7 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-6973Endpoint Manager Mobile (EPMM)2026-05-07CVSS 7.2, EPSS 34%
CVE-2026-1340Endpoint Manager Mobile (EPMM)2026-04-08CVSS 9.8, EPSS 84%
CVE-2026-1281Endpoint Manager Mobile (EPMM)2026-01-29CVSS 9.8, EPSS 82%
CVE-2025-4427Endpoint Manager Mobile (EPMM)2025-05-19CVSS 7.5, EPSS 100%
CVE-2025-4428Endpoint Manager Mobile (EPMM)2025-05-19CVSS 8.8, EPSS 85%
CVE-2023-35081Endpoint Manager Mobile (EPMM)2023-07-31CVSS 7.2, EPSS 64%
CVE-2023-35078Endpoint Manager Mobile (EPMM)2023-07-25ransomware, CVSS 9.8, EPSS 100%

Pulse Connect Secure: 7 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2019-11510Pulse Connect Secure2021-11-03ransomware, CVSS 10.0, EPSS 100%
CVE-2020-8243Pulse Connect Secure2021-11-03CVSS 7.2, EPSS 91%
CVE-2020-8260Pulse Connect Secure2021-11-03CVSS 7.2, EPSS 96%
CVE-2021-22893Pulse Connect Secure2021-11-03ransomware, CVSS 10.0, EPSS 47%
CVE-2021-22894Pulse Connect Secure2021-11-03CVSS 8.8, EPSS 41%
CVE-2021-22899Pulse Connect Secure2021-11-03CVSS 8.8, EPSS 23%
CVE-2021-22900Pulse Connect Secure2021-11-03CVSS 7.2, EPSS 14%

Endpoint Manager (EPM): 5 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2026-1603Endpoint Manager (EPM)2026-03-09CVSS 7.5, EPSS 81%
CVE-2024-13159Endpoint Manager (EPM)2025-03-10CVSS 7.5, EPSS 100%
CVE-2024-13160Endpoint Manager (EPM)2025-03-10CVSS 7.5, EPSS 91%
CVE-2024-13161Endpoint Manager (EPM)2025-03-10CVSS 7.5, EPSS 90%
CVE-2024-29824Endpoint Manager (EPM)2024-10-02CVSS 8.8, EPSS 100%

Cloud Services Appliance (CSA): 3 exploited CVEs

CVEProductAdded to KEVSignals
CVE-2024-9379Cloud Services Appliance (CSA)2024-10-09CVSS 7.2, EPSS 43%
CVE-2024-9380Cloud Services Appliance (CSA)2024-10-09CVSS 7.2, EPSS 63%
CVE-2024-8963Cloud Services Appliance (CSA)2024-09-19CVSS 9.1, EPSS 99%

Other Ivanti products

CVEProductAdded to KEVSignals
CVE-2026-10520Sentry2026-06-11CVSS 10.0, EPSS 100%
CVE-2025-22457Connect Secure, Policy Secure, and ZTA Gateways2025-04-04ransomware, CVSS 9.8, EPSS 100%
CVE-2025-0282Connect Secure, Policy Secure, and ZTA Gateways2025-01-08ransomware, CVSS 9.0, EPSS 100%
CVE-2024-7593Virtual Traffic Manager2024-09-24CVSS 9.8, EPSS 100%
CVE-2024-8190Cloud Services Appliance2024-09-13CVSS 7.2, EPSS 89%
CVE-2021-44529Endpoint Manager Cloud Service Appliance (EPM CSA)2024-03-25ransomware, CVSS 9.8, EPSS 99%
CVE-2024-21893Connect Secure, Policy Secure, and Neurons2024-01-31ransomware, CVSS 8.2, EPSS 100%
CVE-2023-35082Endpoint Manager Mobile (EPMM) and MobileIron Core2024-01-18ransomware, CVSS 9.8, EPSS 100%
CVE-2023-46805Connect Secure and Policy Secure2024-01-10ransomware, CVSS 8.2, EPSS 100%
CVE-2024-21887Connect Secure and Policy Secure2024-01-10ransomware, CVSS 9.1, EPSS 100%
CVE-2023-38035Sentry2023-08-22ransomware, CVSS 9.8, EPSS 100%
CVE-2019-11539Pulse Connect Secure and Pulse Policy Secure2021-11-03ransomware, CVSS 7.2, EPSS 99%
CVE-2020-15505MobileIron Multiple Products2021-11-03CVSS 9.8, EPSS 100%

Common questions about exploited Ivanti CVEs

Which Ivanti vulnerabilities are actively exploited?

As of August 2026, 35 Ivanti CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are Endpoint Manager Mobile (EPMM) (7), Pulse Connect Secure (7), Endpoint Manager (EPM) (5), Cloud Services Appliance (CSA) (3). 12 are linked to ransomware campaigns.

What is the newest exploited Ivanti CVE?

CVE-2026-10520, affecting Sentry, added to the CISA KEV catalog on 2026-06-11. This page refreshes daily, so the newest entry is always first in the table.

How urgent are these Ivanti CVEs?

KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.

Can I ask my own AI about exploited Ivanti CVEs?

Yes. This page includes a free copy-paste AI prompt carrying the newest Ivanti KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed twice a day (5 AM and 3 PM US Central).

All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.

Most searched on Senserva right now

New to a term on this page? CVE, KB, KEV, CVSS, and EPSS are each explained once, on the Senserva security lexicon. Reference: Microsoft CVE and vulnerability management and the Microsoft patching guide.
Provided as is, without warranty; verify against the vendor advisory before acting. Data notice and terms.