FAIL › dossier
Ivanti
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 20%
Ivanti is a private US-based IT management vendor with a critical security posture, evidenced by multiple high-severity RCE and credential exposure vulnerabilities in 2025-2026.
PROFILE
CategorySoftware VendorWhat they doIvanti provides enterprise IT management, endpoint security, and network security solutions including Endpoint Manager, Workspace Control, and Connect Secure.
Websitehttps://www.ivanti.com ↗
SECURITY POSTURE
High-risk vendor with a pattern of critical unauthenticated RCE and credential exposure vulnerabilities in 2026, including multiple CVEs in Endpoint Manager and EPMM.
Notable failures
- 2026-06-11 CVE-2026-10520: Unauthenticated root access via command injection in Ivanti Sentry
- 2026-04-08 CVE-2026-1340: Unauthenticated RCE via code injection in Ivanti EPMM
- 2026-03-09 CVE-2026-1603: Credential leak via authentication bypass in Ivanti Endpoint Manager
- 2026-05-07 CVE-2026-6973: RCE for authenticated admins via improper input validation in Ivanti EPMM
- 2025-06-11: Hardcoded cryptographic keys exposed SQL credentials in Ivanti Workspace Control
Patterns: Repeated unpatched edge-device RCEs; Hardcoded cryptographic key flaws; Authentication bypass enabling credential theft
FAILURE HISTORY · 41
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-01-29 | CVE-2026-1281 | high | Ivanti EPMM exposed to unauthenticated RCE due to code injection flaw |
| 2025-04-04 | CVE-2025-22457 | critical | Ivanti Connect Secure gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution, linked to ransomware. |
| 2026-06-11 | CVE-2026-10520 | high | Ivanti Sentry allows remote unauthenticated root access via command injection when appliances are unmanaged and externally reachable. |
| 2026-04-08 | CVE-2026-1340 | high | Ivanti EPMM allows unauthenticated remote code execution via code injection, enabling attackers to compromise endpoint management systems without credentials. |
| 2026-03-09 | CVE-2026-1603 | high | Ivanti Endpoint Manager allows remote unauthenticated attackers to bypass authentication and leak stored credentials via an alternate path. |
| 2025-01-08 | CVE-2025-0282 | critical | Ivanti Connect Secure, Policy Secure, and ZTA Gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution. |
| 2024-10-02 | CVE-2024-29824 | high | Ivanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network. |
| 2024-09-24 | CVE-2024-7593 | high | Ivanti Virtual Traffic Manager allows remote attackers to create admin accounts via an authentication bypass. |
| 2024-09-19 | CVE-2024-8963 | high | Ivanti CSA path traversal vulnerability enables remote unauthenticated access and, when combined with CVE-2024-8190, allows arbitrary command execution. |
| 2024-03-25 | CVE-2021-44529 | critical | An unauthenticated code injection flaw in Ivanti's Endpoint Manager Cloud Service Appliance allowed attackers to execute malicious code, directly enabling ransomware campaigns. |
| 2024-01-31 | CVE-2024-21893 | critical | Ivanti Connect Secure, Policy Secure, and Neurons suffered an actively exploited SSRF vulnerability in their SAML component that bypassed authentication to access restricted resources. |
| 2024-01-18 | CVE-2023-35082 | critical | An authentication bypass flaw in Ivanti EPMM and MobileIron Core allowed attackers to access restricted resources, directly enabling ransomware campaigns. |
| 2024-01-10 | CVE-2024-21887 | critical | Ivanti Connect Secure and Policy Secure suffered a critical command injection vulnerability that was actively exploited in the wild to execute arbitrary code on appliances. |
| 2024-01-10 | CVE-2023-46805 | critical | Ivanti Connect Secure and Policy Secure suffered an authentication bypass vulnerability that allowed attackers to access restricted resources, which could be combined with a command injection flaw for full system compromise. |
| 2023-08-22 | CVE-2023-38035 | critical | Ivanti Sentry's insufficiently restrictive Apache HTTPD configuration allowed attackers to bypass authentication controls on its administrative interface. |
| 2023-07-25 | CVE-2023-35078 | critical | Ivanti Endpoint Manager Mobile suffered an authentication bypass allowing unauthenticated access to PII and device configuration. |
| 2025-05-19 | CVE-2025-4428 | high | Ivanti EPMM API code injection allows remote execution of arbitrary code by authenticated attackers |
| 2025-05-19 | CVE-2025-4427 | high | Ivanti EPMM API flaw allows unauthorized access via crafted requests |
| 2021-11-03 | CVE-2019-11510 | critical | Ivanti Pulse Connect Secure allowed unauthenticated attackers to read arbitrary files via a specially crafted URI, and was actively exploited in the wild, often linked to ransomware attacks. |
| 2021-11-03 | CVE-2019-11539 | critical | Authenticated admins of Ivanti Pulse Connect Secure/Policy Secure could inject and execute commands via the web interface, actively exploited in ransomware attacks. |
| 2021-11-03 | CVE-2021-22893 | critical | Ivanti Pulse Connect Secure's use-after-free vulnerability allowed unauthenticated attackers to execute code remotely, and is actively being exploited in ransomware attacks. |
| 2023-07-31 | CVE-2023-35081 | high | An authenticated administrator of Ivanti Endpoint Manager Mobile (EPMM) can write malicious files to the server via a path traversal vulnerability, potentially bypassing access controls and enabling further compromise. |
| 2026-05-07 | CVE-2026-6973 | high | Ivanti EPMM allows remote code execution for authenticated admins via improper input validation. |
| 2024-10-09 | CVE-2024-9380 | high | Ivanti CSA admin console allows authenticated attackers to execute arbitrary OS commands via command injection. |
| 2024-09-13 | CVE-2024-8190 | high | Ivanti Cloud Services Appliance allows authenticated admins to execute arbitrary OS commands via command injection in the admin console. |
| 2021-11-03 | CVE-2021-22900 | high | Ivanti Pulse Connect Secure contains an unrestricted file upload vulnerability that allows an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface. |
| 2021-11-03 | CVE-2020-15505 | high | Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution. |
| 2021-11-03 | CVE-2020-8243 | high | Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution. |
| 2021-11-03 | CVE-2021-22894 | high | Ivanti Pulse Connect Secure Collaboration Suite contains a buffer overflow vulnerabilities that allows a remote authenticated users to execute code as the root user via maliciously crafted meeting room. |
| 2021-11-03 | CVE-2020-8260 | high | Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction. |
| 2021-11-03 | CVE-2021-22899 | high | Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles. |
| 2025-03-10 | CVE-2024-13159 | high | Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely. |
| 2025-03-10 | CVE-2024-13160 | high | Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely. |
| 2025-03-10 | CVE-2024-13161 | high | Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely. |
| 2024-10-09 | CVE-2024-9379 | high | Ivanti CSA admin console SQL injection allows authenticated admins to execute arbitrary SQL statements in versions prior to 5.0.2. |
| 2026-06-09 | CVE-2026-10523 | critical | CVE-2026-10523: An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10 |
| 2025-04-03 | CVE-2025-22457 | critical | CVE-2025-22457: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, |
| 2025-01-08 | CVE-2025-0282 | critical | CVE-2025-0282: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, |
| 2024-01-12 | CVE-2024-21887 | critical | CVE-2024-21887: A command injection vulnerability in web components of Ivanti Connect Secure (9. |
| 2023-07-25 | CVE-2023-35078 | critical | CVE-2023-35078: An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users |
| 2021-12-08 | CVE-2021-44529 | critical | CVE-2021-44529: A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
Critical vulnerability in core products poses significant risk to enterprise security posture.
Critical vulnerability in core products poses significant risk to enterprise security posture.
"Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution."
FEDRAMP CATALOG PRODUCTS · 2
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) | Authorized | Moderate |
| Ivanti Neurons for MDM (Formerly MobileIron) | Authorized | Moderate |
DOSSIER SOURCES
- Credo Technology Group Holding (CRDO) Company Profile & Description · stockanalysis.com
- nVent Electric (NVT) Company Profile, History, Products & Services · www.financecharts.com
- Ivanti Connect Secure End of Life: Migration Options 2026 · jimber.io
- GitHub - SecureWithUmer/CVE-2026-PoCs: A community-curated, verified ... · github.com
- Ivanti Workspace Control Exposes SQL Credentials Through Hardcoded Key ... · dailysecurityreview.com
Open questions: Ivanti's remediation timeline for 2026 CVEs · Impact of these vulnerabilities on CMMC compliance status
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 17:50:07.686099+00:00