27 Total CVEs
27 AI Analyzed
6 CISA KEV
8 Critical

Profile

22.2% ended up actively exploited 6 of 27 added to CISA KEV
30% rated critical (CVSS 9.0+) 8 critical, 19 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

17 CVEs in the last 12 months

Products

  • Endpoint Manager2
  • EPMM before2
  • Sentry2
  • Neurons for ITSM1
  • Xtraction before1
  • Endpoint Manager Mobile (EPMM)1
  • DSM before1
  • vTM (Virtual Traffic Manager)1

8 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-27 of 27 CVEs
CVE-2026-9614
Analyzed
8.8
Ivanti Neurons for ITSM

An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrat...

2026-06-02
CVE-2026-8111
Analyzed
8.8
Ivanti Endpoint Manager

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code exec...

2026-05-13
CVE-2026-8043
Analyzed
9.6
Ivanti Xtraction before

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arb...

2026-05-13
CVE-2026-6973
KEV Analyzed
9.5
Ivanti Endpoint Manager Mobile (EPMM)

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability - Active in CISA KEV catalog.

2026-05-08
CVE-2026-5787
Analyzed
8.9
Ivanti EPMM before

An Improper Certificate Validation in Ivanti EPMM before versions 12

2026-05-08
CVE-2026-5786
Analyzed
8.8
Ivanti EPMM before

An Improper Access Control vulnerability in Ivanti EPMM before versions 12

2026-05-08
CVE-2026-3483
Analyzed
7.8
Ivanti DSM before

An exposed dangerous method in Ivanti DSM before version 2026

2026-03-11
CVE-2026-1603
KEV Analyzed
8.6
Ivanti Endpoint Manager

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credentia...

2026-02-11
CVE-2026-1340
KEV Analyzed
9.8
Ivanti Multiple Products

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

2026-01-30
CVE-2026-1281
KEV Analyzed
9.8
Ivanti Multiple Products

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

2026-01-30
CVE-2026-10523
Analyzed
9.9
Ivanti Sentry

An authentication bypass vulnerability in Ivanti Sentry allows unauthenticated attackers to create arbitrary administrative accounts and gain full acc...

2026-06-10
CVE-2026-10520
KEV Analyzed
10
Ivanti Sentry

A critical OS command injection vulnerability in Ivanti Sentry allows remote unauthenticated users to achieve root-level remote code execution.

2026-06-10
CVE-2025-9872
Analyzed
8.8
Ivanti Multiple Products

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve r...

2025-09-09
CVE-2025-9713
Analyzed
8.8
Ivanti Multiple Products

Path traversal in Ivanti Endpoint Manager allows a remote unauthenticated attacker to achieve remote code execution

2025-10-13
CVE-2025-9712
Analyzed
8.8
Ivanti Multiple Products

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve r...

2025-09-09
CVE-2025-6996
Analyzed
8.4
Ivanti Multiple Products

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated...

2025-07-10
CVE-2025-6995
Analyzed
8.4
Ivanti Multiple Products

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated...

2025-07-10
CVE-2025-55148
Analyzed
7.6
Ivanti Multiple Products

Missing authorization in Ivanti Connect Secure before 22

2025-09-09
CVE-2025-55147
Analyzed
8.8
Ivanti Multiple Products

CSRF in Ivanti Connect Secure before 22

2025-09-09
CVE-2025-55145
Analyzed
8.9
Ivanti Multiple Products

Missing authorization in Ivanti Connect Secure before 22

2025-09-09
CVE-2025-55142
Analyzed
8.8
Ivanti Multiple Products

Missing authorization in Ivanti Connect Secure before 22

2025-09-09
CVE-2025-55141
Analyzed
8.8
Ivanti Multiple Products

Missing authorization in Ivanti Connect Secure before 22

2025-09-09
CVE-2025-13662
Analyzed
7.8
Ivanti Multiple Products

Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a...

2025-12-10
CVE-2025-13659
Analyzed
8.8
Ivanti Multiple Products

Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attac...

2025-12-10
CVE-2025-11622
Analyzed
7.8
Ivanti Multiple Products

Insecure deserialization in Ivanti Endpoint Manager allows a local authenticated attacker to escalate their privileges

2025-10-13
CVE-2025-10573
Analyzed
9.6
Ivanti Multiple Products

Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the co...

2025-12-10
CVE-2024-7593
KEV Analyzed
9.8
Ivanti vTM (Virtual Traffic Manager)

An authentication bypass vulnerability in the Ivanti vTM admin panel allows remote unauthenticated attackers to gain unauthorized administrative acces...

2026-06-05