FAIL › dossier
Ivanti
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 20%
Ivanti is a private US-based IT management vendor with a critical security posture, evidenced by multiple high-severity RCE and credential exposure vulnerabilities in 2025-2026.
PROFILE
CategorySoftware VendorWhat they doIvanti provides enterprise IT management, endpoint security, and network security solutions including Endpoint Manager, Workspace Control, and Connect Secure.
Websitehttps://www.ivanti.com ↗
SECURITY POSTURE
High-risk vendor with a pattern of critical unauthenticated RCE and credential exposure vulnerabilities in 2026, including multiple CVEs in Endpoint Manager and EPMM.
Notable failures
- 2026-06-11 CVE-2026-10520: Unauthenticated root access via command injection in Ivanti Sentry
- 2026-04-08 CVE-2026-1340: Unauthenticated RCE via code injection in Ivanti EPMM
- 2026-03-09 CVE-2026-1603: Credential leak via authentication bypass in Ivanti Endpoint Manager
- 2026-05-07 CVE-2026-6973: RCE for authenticated admins via improper input validation in Ivanti EPMM
- 2025-06-11: Hardcoded cryptographic keys exposed SQL credentials in Ivanti Workspace Control
Patterns: Repeated unpatched edge-device RCEs; Hardcoded cryptographic key flaws; Authentication bypass enabling credential theft
FAILURE HISTORY · 42
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-01-29 | CVE-2026-1281 | high | Ivanti EPMM exposed to unauthenticated RCE due to code injection flaw |
| 2025-04-04 | CVE-2025-22457 | critical | Ivanti Connect Secure gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution, linked to ransomware. |
| 2026-06-11 | CVE-2026-10520 | high | Ivanti Sentry allows remote unauthenticated root access via command injection when appliances are unmanaged and externally reachable. |
| 2026-04-08 | CVE-2026-1340 | high | Ivanti EPMM allows unauthenticated remote code execution via code injection, enabling attackers to compromise endpoint management systems without credentials. |
| 2026-03-09 | CVE-2026-1603 | high | Ivanti Endpoint Manager allows remote unauthenticated attackers to bypass authentication and leak stored credentials via an alternate path. |
| 2025-01-08 | CVE-2025-0282 | critical | Ivanti Connect Secure, Policy Secure, and ZTA Gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution. |
| 2024-10-02 | CVE-2024-29824 | high | Ivanti Endpoint Manager (EPM) Core server is vulnerable to unauthenticated SQL injection enabling arbitrary code execution within the same network. |
| 2024-09-24 | CVE-2024-7593 | high | Ivanti Virtual Traffic Manager allows remote attackers to create admin accounts via an authentication bypass. |
| 2024-09-19 | CVE-2024-8963 | high | Ivanti CSA path traversal vulnerability enables remote unauthenticated access and, when combined with CVE-2024-8190, allows arbitrary command execution. |
| 2024-03-25 | CVE-2021-44529 | critical | An unauthenticated code injection flaw in Ivanti's Endpoint Manager Cloud Service Appliance allowed attackers to execute malicious code, directly enabling ransomware campaigns. |
| 2024-01-31 | CVE-2024-21893 | critical | Ivanti Connect Secure, Policy Secure, and Neurons suffered an actively exploited SSRF vulnerability in their SAML component that bypassed authentication to access restricted resources. |
| 2024-01-18 | CVE-2023-35082 | critical | An authentication bypass flaw in Ivanti EPMM and MobileIron Core allowed attackers to access restricted resources, directly enabling ransomware campaigns. |
| 2024-01-10 | CVE-2023-46805 | critical | Ivanti Connect Secure and Policy Secure suffered an authentication bypass vulnerability that allowed attackers to access restricted resources, which could be combined with a command injection flaw for full system compromise. |
| 2024-01-10 | CVE-2024-21887 | critical | Ivanti Connect Secure and Policy Secure suffered a critical command injection vulnerability that was actively exploited in the wild to execute arbitrary code on appliances. |
| 2023-08-22 | CVE-2023-38035 | critical | Ivanti Sentry's insufficiently restrictive Apache HTTPD configuration allowed attackers to bypass authentication controls on its administrative interface. |
| 2023-07-25 | CVE-2023-35078 | critical | Ivanti Endpoint Manager Mobile suffered an authentication bypass allowing unauthenticated access to PII and device configuration. |
| 2021-11-03 | CVE-2021-22899 | high | Ivanti Pulse Connect Secure suffered a command injection vulnerability allowing remote authenticated users to execute arbitrary code via Windows File Resource Profiles. |
| 2021-11-03 | CVE-2021-22894 | high | Ivanti Pulse Connect Secure suffered a buffer overflow allowing remote authenticated users to execute root code via malicious meeting rooms. |
| 2021-11-03 | CVE-2020-15505 | high | Ivanti MobileIron products suffered a remote code execution vulnerability that was actively exploited in the wild. |
| 2025-05-19 | CVE-2025-4428 | high | Ivanti EPMM API code injection allows remote execution of arbitrary code by authenticated attackers |
| 2025-05-19 | CVE-2025-4427 | high | Ivanti EPMM API flaw allows unauthorized access via crafted requests |
| 2021-11-03 | CVE-2019-11510 | critical | Ivanti Pulse Connect Secure allowed unauthenticated attackers to read arbitrary files via a specially crafted URI, and was actively exploited in the wild, often linked to ransomware attacks. |
| 2021-11-03 | CVE-2019-11539 | critical | Authenticated admins of Ivanti Pulse Connect Secure/Policy Secure could inject and execute commands via the web interface, actively exploited in ransomware attacks. |
| 2021-11-03 | CVE-2021-22893 | critical | Ivanti Pulse Connect Secure's use-after-free vulnerability allowed unauthenticated attackers to execute code remotely, and is actively being exploited in ransomware attacks. |
| 2021-11-03 | CVE-2020-8260 | high | An authenticated attacker could execute arbitrary code via uncontrolled gzip extraction in Ivanti Pulse Connect Secure. |
| 2023-07-31 | CVE-2023-35081 | high | An authenticated administrator of Ivanti Endpoint Manager Mobile (EPMM) can write malicious files to the server via a path traversal vulnerability, potentially bypassing access controls and enabling further compromise. |
| 2026-05-07 | CVE-2026-6973 | high | Ivanti EPMM allows remote code execution for authenticated admins via improper input validation. |
| 2024-10-09 | CVE-2024-9380 | high | Ivanti CSA admin console allows authenticated attackers to execute arbitrary OS commands via command injection. |
| 2024-09-13 | CVE-2024-8190 | high | Ivanti Cloud Services Appliance allows authenticated admins to execute arbitrary OS commands via command injection in the admin console. |
| 2021-11-03 | CVE-2021-22900 | high | An authenticated admin on Ivanti Pulse Connect Secure could upload malicious archives to write arbitrary files via an unrestricted file upload flaw. |
| 2021-11-03 | CVE-2020-8243 | high | An authenticated attacker could upload a custom template to Pulse Connect Secure to perform code execution. |
| 2025-03-10 | CVE-2024-13159 | high | Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely. |
| 2025-03-10 | CVE-2024-13160 | high | Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely. |
| 2025-03-10 | CVE-2024-13161 | high | Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely. |
| 2024-10-09 | CVE-2024-9379 | high | Ivanti CSA admin console SQL injection allows authenticated admins to execute arbitrary SQL statements in versions prior to 5.0.2. |
| 2026-06-09 | CVE-2026-10523 | critical | CVE-2026-10523: An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10 |
| 2025-04-03 | CVE-2025-22457 | critical | CVE-2025-22457: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, |
| 2025-01-08 | CVE-2025-0282 | critical | CVE-2025-0282: A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, |
| 2024-01-12 | CVE-2024-21887 | critical | CVE-2024-21887: A command injection vulnerability in web components of Ivanti Connect Secure (9. |
| 2023-07-25 | CVE-2023-35078 | critical | CVE-2023-35078: An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users |
| 2021-12-08 | CVE-2021-44529 | critical | CVE-2021-44529: A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) |
| 2021-04-23 | CVE-2021-22893 | critical | CVE-2021-22893: Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication b |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.60
Unrestricted file upload flaw in admin interface allows malicious archive writes, exposing enterprise networks to compromise; no praise found in coverage.
synthesissevere-fallout-0.60
Ivanti's CVE-2019-11510 arbitrary file read flaw was widely recognized as a critical, unauthenticated remote exploit risk, though the provided sources lack direct press commentary or vendor response d
synthesissevere-fallout-0.60
Vulnerability allows remote code execution without authentication, representing a critical security failure.
synthesissevere-fallout-0.60
Ivanti faced severe criticism for a critical command injection flaw in its admin interface, allowing authenticated attackers to execute arbitrary commands, which was widely flagged as a high-severity
synthesissevere-fallout-0.80
Critical vulnerability in core products poses significant risk to enterprise security posture.
synthesissevere-fallout-0.60
Vulnerability in admin interface allowing code execution via template upload is a severe flaw, though no specific press condemnation or authority fallout is detailed in the provided sources.
synthesissevere-fallout-0.60
Vulnerability allows remote authenticated users to execute code as root, representing a critical security failure with severe fallout.
synthesissevere-fallout-0.60
Vulnerability allows remote code execution via command injection, a critical flaw with severe security implications.
synthesissevere-fallout-0.60
CISA KEV listing and active exploitation indicate severe fallout, though vendor-specific press coverage is absent in the provided sources.
synthesissevere-fallout-0.60
Vulnerability exploited in the wild, causing real-world attacks on critical infrastructure like Nominet, with no praise for vendor response in provided sources.
No relevant content regarding Ivanti or CVE-2020-8243.
Critical vulnerability in core products poses significant risk to enterprise security posture.
"Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution."
Critical unauthenticated remote code execution flaw in license services.
"Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services."
CVE Find page unrelated to CVE-2021-22900; no sentiment toward Ivanti.
Severe vulnerability in admin interface allowing code execution via template upload.
"Ivanti Pulse Connect Secure contains an unspecified vulnerability in the admin web interface that could allow an authenticated attacker to upload a custom template to perform code execution."
No specific sentiment toward Ivanti regarding CVE-2020-8243; source text is largely unrelated promotional content.
No relevant content regarding Ivanti or CVE-2020-8243.
No relevant content regarding Ivanti or CVE-2020-8243.
No relevant content regarding Ivanti or CVE-2020-8243.
No relevant content regarding Ivanti or CVE-2020-8243.
NVD entry confirms critical unauthenticated remote file read flaw, implying severe risk but lacks press sentiment.
"Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI."
No relevant security commentary; unrelated procurement page.
Irrelevant; unrelated article on sextortion.
No direct commentary; CISA catalog page lacks specific vendor sentiment.
Irrelevant; CVE database homepage.
Irrelevant; unrelated CVE database page.
Irrelevant; unrelated Cisco hardening advisory.
Severe vulnerability in admin interface allowing command execution, widely condemned as a critical flaw requiring urgent patching.
"Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands."
NVD entry confirms active exploitation and code execution, implying severe fallout.
"Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction."
No vendor-specific sentiment; CISA catalog entry only.
FEDRAMP CATALOG PRODUCTS · 2
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Ivanti Neurons for ITSM (Formerly Service Manager) | Authorized | Moderate |
| Ivanti Neurons for MDM (Formerly MobileIron) | Authorized | Moderate |
DOSSIER SOURCES
- Credo Technology Group Holding (CRDO) Company Profile & Description · stockanalysis.com
- nVent Electric (NVT) Company Profile, History, Products & Services · www.financecharts.com
- Ivanti Connect Secure End of Life: Migration Options 2026 · jimber.io
- GitHub - SecureWithUmer/CVE-2026-PoCs: A community-curated, verified ... · github.com
- Ivanti Workspace Control Exposes SQL Credentials Through Hardcoded Key ... · dailysecurityreview.com
Open questions: Ivanti's remediation timeline for 2026 CVEs · Impact of these vulnerabilities on CMMC compliance status
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 17:50:07.686099+00:00