Skip to content
COOEY

FAIL › dossier

Ivanti

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 20%

Ivanti is a private US-based IT management vendor with a critical security posture, evidenced by multiple high-severity RCE and credential exposure vulnerabilities in 2025-2026.

PROFILE
CategorySoftware VendorWhat they doIvanti provides enterprise IT management, endpoint security, and network security solutions including Endpoint Manager, Workspace Control, and Connect Secure. Websitehttps://www.ivanti.com ↗
SECURITY POSTURE

High-risk vendor with a pattern of critical unauthenticated RCE and credential exposure vulnerabilities in 2026, including multiple CVEs in Endpoint Manager and EPMM.

Notable failures
  • 2026-06-11 CVE-2026-10520: Unauthenticated root access via command injection in Ivanti Sentry
  • 2026-04-08 CVE-2026-1340: Unauthenticated RCE via code injection in Ivanti EPMM
  • 2026-03-09 CVE-2026-1603: Credential leak via authentication bypass in Ivanti Endpoint Manager
  • 2026-05-07 CVE-2026-6973: RCE for authenticated admins via improper input validation in Ivanti EPMM
  • 2025-06-11: Hardcoded cryptographic keys exposed SQL credentials in Ivanti Workspace Control
Patterns: Repeated unpatched edge-device RCEs; Hardcoded cryptographic key flaws; Authentication bypass enabling credential theft
FAILURE HISTORY · 41
DATEEVENTSEVSUMMARY
2026-01-29 CVE-2026-1281 high Ivanti EPMM exposed to unauthenticated RCE due to code injection flaw
2025-04-04 CVE-2025-22457 critical Ivanti Connect Secure gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution, linked to ransomware.
2026-06-11 CVE-2026-10520 high Ivanti Sentry allows remote unauthenticated root access via command injection when appliances are unmanaged and externally reachable.
2026-04-08 CVE-2026-1340 high Ivanti EPMM allows unauthenticated remote code execution via code injection, enabling attackers to compromise endpoint management systems without credentials.
2026-03-09 CVE-2026-1603 high Ivanti Endpoint Manager allows remote unauthenticated attackers to bypass authentication and leak stored credentials via an alternate path.
2025-01-08 CVE-2025-0282 critical Ivanti Connect Secure, Policy Secure, and ZTA Gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution.
2024-10-02 CVE-2024-29824 high Ivanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network.
2024-09-24 CVE-2024-7593 high Ivanti Virtual Traffic Manager allows remote attackers to create admin accounts via an authentication bypass.
2024-09-19 CVE-2024-8963 high Ivanti CSA path traversal vulnerability enables remote unauthenticated access and, when combined with CVE-2024-8190, allows arbitrary command execution.
2024-03-25 CVE-2021-44529 critical An unauthenticated code injection flaw in Ivanti's Endpoint Manager Cloud Service Appliance allowed attackers to execute malicious code, directly enabling ransomware campaigns.
2024-01-31 CVE-2024-21893 critical Ivanti Connect Secure, Policy Secure, and Neurons suffered an actively exploited SSRF vulnerability in their SAML component that bypassed authentication to access restricted resources.
2024-01-18 CVE-2023-35082 critical An authentication bypass flaw in Ivanti EPMM and MobileIron Core allowed attackers to access restricted resources, directly enabling ransomware campaigns.
2024-01-10 CVE-2024-21887 critical Ivanti Connect Secure and Policy Secure suffered a critical command injection vulnerability that was actively exploited in the wild to execute arbitrary code on appliances.
2024-01-10 CVE-2023-46805 critical Ivanti Connect Secure and Policy Secure suffered an authentication bypass vulnerability that allowed attackers to access restricted resources, which could be combined with a command injection flaw for full system compromise.
2023-08-22 CVE-2023-38035 critical Ivanti Sentry's insufficiently restrictive Apache HTTPD configuration allowed attackers to bypass authentication controls on its administrative interface.
2023-07-25 CVE-2023-35078 critical Ivanti Endpoint Manager Mobile suffered an authentication bypass allowing unauthenticated access to PII and device configuration.
2025-05-19 CVE-2025-4428 high Ivanti EPMM API code injection allows remote execution of arbitrary code by authenticated attackers
2025-05-19 CVE-2025-4427 high Ivanti EPMM API flaw allows unauthorized access via crafted requests
2021-11-03 CVE-2019-11510 critical Ivanti Pulse Connect Secure allowed unauthenticated attackers to read arbitrary files via a specially crafted URI, and was actively exploited in the wild, often linked to ransomware attacks.
2021-11-03 CVE-2019-11539 critical Authenticated admins of Ivanti Pulse Connect Secure/Policy Secure could inject and execute commands via the web interface, actively exploited in ransomware attacks.
2021-11-03 CVE-2021-22893 critical Ivanti Pulse Connect Secure's use-after-free vulnerability allowed unauthenticated attackers to execute code remotely, and is actively being exploited in ransomware attacks.
2023-07-31 CVE-2023-35081 high An authenticated administrator of Ivanti Endpoint Manager Mobile (EPMM) can write malicious files to the server via a path traversal vulnerability, potentially bypassing access controls and enabling further compromise.
2026-05-07 CVE-2026-6973 high Ivanti EPMM allows remote code execution for authenticated admins via improper input validation.
2024-10-09 CVE-2024-9380 high Ivanti CSA admin console allows authenticated attackers to execute arbitrary OS commands via command injection.
2024-09-13 CVE-2024-8190 high Ivanti Cloud Services Appliance allows authenticated admins to execute arbitrary OS commands via command injection in the admin console.
2021-11-03 CVE-2021-22900 high Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.
2021-11-03 CVE-2020-15505 high Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.
2021-11-03 CVE-2020-8243 high Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution.
2021-11-03 CVE-2021-22894 high Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room.
2021-11-03 CVE-2020-8260 high Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.
2021-11-03 CVE-2021-22899 high Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.
2025-03-10 CVE-2024-13159 high Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
2025-03-10 CVE-2024-13160 high Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
2025-03-10 CVE-2024-13161 high Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
2024-10-09 CVE-2024-9379 high Ivanti CSA admin console SQL injection allows authenticated admins to execute arbitrary SQL statements in versions prior to 5.0.2.
2026-06-09 CVE-2026-10523 critical CVE-2026-10523: An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10
2025-04-03 CVE-2025-22457 critical CVE-2025-22457: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6,
2025-01-08 CVE-2025-0282 critical CVE-2025-0282: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5,
2024-01-12 CVE-2024-21887 critical CVE-2024-21887: A command injection vulnerability in web components of Ivanti Connect Secure (9.
2023-07-25 CVE-2023-35078 critical CVE-2023-35078: An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users
2021-12-08 CVE-2021-44529 critical CVE-2021-44529: A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA)
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
Critical vulnerability in core products poses significant risk to enterprise security posture.
cooey ↗severe-fallout-0.80
Critical vulnerability in core products poses significant risk to enterprise security posture.
"Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution."
FEDRAMP CATALOG PRODUCTS · 2
Open questions: Ivanti's remediation timeline for 2026 CVEs · Impact of these vulnerabilities on CMMC compliance status
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 17:50:07.686099+00:00