ivanti
22 known vulnerabilities affecting ivanti products.
Products
neurons_for_itsm 8
connect_secure 6
policy_secure 5
standalone_sentry 2
xtraction 2
neurons_for_zero-trust_access 2
endpoint_manager_mobile 2
endpoint_manager_cloud_services_appliance 1
zero_trust_access_gateway 1
secure_access_client 1
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2023-35078 | Act now | 100.0% | 9.8 | ● | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users … |
| CVE-2024-21887 | Act now | 100.0% | 9.1 | ● | A command injection vulnerability in web components of Ivanti Connect Secure (9.… |
| CVE-2024-21893 | Act now | 100.0% | 8.2 | ● | A server-side request forgery vulnerability in the SAML component of Ivanti Conn… |
| CVE-2023-46805 | Act now | 100.0% | 8.2 | ● | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 2… |
| CVE-2025-22457 | Act now | 100.0% | 9.0 | ● | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, … |
| CVE-2025-0282 | Act now | 100.0% | 9.0 | ● | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, … |
| CVE-2026-10520 | Act now | 99.9% | 10.0 | ● | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6… |
| CVE-2021-44529 | Act now | 99.1% | 9.8 | ● | A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) … |
| CVE-2021-22893 | Act now | 47.2% | 10.0 | ● | Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication b… |
| CVE-2026-10523 | High | 51.9% | 9.9 | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10… | |
| CVE-2026-12744 | Medium | 2.2% | 9.8 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef… | |
| CVE-2026-12745 | Medium | 2.1% | 9.8 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef… | |
| CVE-2026-12648 | Medium | 1.5% | 8.8 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef… | |
| CVE-2026-12650 | Medium | 1.5% | 9.9 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef… | |
| CVE-2026-12651 | Medium | 1.5% | 8.8 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM bef… | |
| CVE-2026-12645 | Medium | 1.2% | 9.9 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 a… | |
| CVE-2026-12646 | Medium | 1.2% | 9.9 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 a… | |
| CVE-2026-12647 | Medium | 1.2% | 9.9 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 a… | |
| CVE-2026-14903 | Medium | 1.0% | 7.7 | Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote auth… | |
| CVE-2026-18851 | Medium | 1.0% | 8.8 | Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0… | |
| CVE-2026-8992 | Medium | 0.6% | 8.8 | An improper certificate validation vulnerability in Ivanti Secure Access Client … | |
| CVE-2026-14902 | Low | 0.4% | 4.0 | An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote una… |