Ivanti
Security Risk Profile
59
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 900 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 26, 2016 to present
900
Total CVEs
422
Critical+High
76
Exploited
381
Unpatched
Threat Assessment
Avg CVSS
8
Base severity
Avg EPSS
8%
Exploit probability
Unpatched
381
Critical/High
Risk Level
59/100
medium
⚠️ 76 Active Exploits⚡ 50 Zero-Days🆕 27Fresh (<7d)📈 44 in Last 30 Days
Severity Distribution
Critical
159High
263Medium
101Low
0Exploit Likelihood
>50% chance
420-50%
05-20%
3<5%
51Age Distribution
Common Weaknesses (CWE)
1
SQL Injection
70
2
Path Traversal
48
3
Command Injection
28
4
XSS
24
5
Buffer Overflow
21
Most Affected Products
1. Ivanti Connect Secure2485
2. PulseSecure Pulse Connect Secure1129
3. Ivanti Endpoint Manager992
4. Ivanti Policy Secure843
5. PulseSecure Pulse Policy Secure608
Recent Vulnerabilities
See more →CVE-2026-8992
CVSS 8.8EPSS 0%high
5/22/2026🔧 No Patch
CVE-2026-8111
CVSS 8.8EPSS 0%high
5/12/2026🔧 No Patch
CVE-2026-8110
CVSS 7.8EPSS 0%high
5/12/2026🔧 No Patch
CVE-2026-8109
CVSS 6.5EPSS 0%medium
5/12/2026🔧 No Patch
CVE-2026-8051
CVSS 7.2EPSS 1%high
5/12/2026🔧 No Patch
CVE-2026-7432
CVSS 7.8EPSS 0%high
5/12/2026🔧 No Patch
CVE-2026-7431
CVSS 4.4EPSS 0%medium
5/12/2026🔧 No Patch
CVE-2026-8043
CVSS 9.6EPSS 0%critical
5/12/2026🔧 No Patch
ZDI-26-308
unknown
Ivanti Endpoint Manager RemoteControlAuth Exposed Dangerous Method Information Disclosure Vulnerability
5/12/2026🔧 No Patch
ZDI-CAN-28617
unknown
ZDI-26-308: Ivanti Endpoint Manager RemoteControlAuth Exposed Dangerous Method Information Disclosure Vulnerability
5/12/2026🔧 No Patch
Monitor Ivanti in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.