Where
-Infinity
0

Vendor Risk Score

See how ivanti compares to other vendors in security performance

View Risk Score →

Software

Ivanti Secure Access ClientAn improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows…

Risk 56
Severity
8.8
EPSS
0.12%
First published (updated )

Ivanti Endpoint ManagerSQL Injection

Risk 56
Severity
8.8
EPSS
0.35%
First published (updated )

Ivanti Endpoint ManagerIncorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 all…

Risk 51
Severity
7.8
EPSS
0.03%
First published (updated )

Ivanti Endpoint ManagerAn exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 al…

Risk 27
Severity
6.5
EPSS
0.12%
First published (updated )

Ivanti Virtual Traffic ManagerOS Command Injection, Command Injection

Risk 50
Severity
7.2
EPSS
1.46%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Ivanti Secure Access ClientRace Condition

Risk 51
Severity
7.8
EPSS
0.03%
First published (updated )

Ivanti Secure Access ClientAn incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.…

Risk 21
Severity
4.4
EPSS
0.04%
First published (updated )

Ivanti XtractionExternal control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authentica…

Risk 49
Severity
9.6
EPSS
0.12%
First published (updated )

Ivanti Endpoint ManagerIvanti Endpoint Manager RemoteControlAuth Exposed Dangerous Method Information Disclosure Vulnerability

Risk 43
First published (updated )
Advisory
ZDI-26-308

Ivanti Endpoint ManagerZDI-26-308: Ivanti Endpoint Manager RemoteControlAuth Exposed Dangerous Method Information Disclosure Vulnerability

Risk 48
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerCISA gives feds four days to patch Ivanti flaw exploited as zero-day

First published (updated )

BleepingComputerCISA gives feds four days to patch Ivanti flaw exploited as zero-day

First published (updated )

Ivanti Endpoint Manager MobileAn Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 a…

Risk 69
Severity
9.1
First published (updated )

Ivanti Endpoint Manager MobileAn Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a …

Risk 89
Severity
9.8
First published (updated )

Ivanti Endpoint Manager MobileImproper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allo…

Risk 48
Severity
9.1
EPSS
0.06%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerIvanti warns of new EPMM flaw exploited in zero-day attacks

First published (updated )

Ivanti Endpoint Manager MobileAn Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8…

Risk 82
Severity
8.8
First published (updated )

Ivanti Endpoint Manager MobileIvanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Risk 67
Severity
7.2
EPSS
6.39%
First published (updated )

Ivanti N-ITSMXSS

Risk 25
Severity
5.4
EPSS
0.07%
First published (updated )

Ivanti N-ITSMImproper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote auth…

Risk 24
Severity
5.7
EPSS
0.11%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerCISA orders feds to patch exploited Ivanti EPMM flaw by Sunday

First published (updated )

Ivanti DSMAn exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attac…

Risk 51
Severity
7.8
EPSS
0.03%
First published (updated )

BleepingComputerCISA: Recently patched Ivanti EPM flaw now actively exploited

First published (updated )

Ivanti Endpoint ManagerZDI-26-080: Ivanti Endpoint Manager AuthHelper Authentication Bypass Vulnerability

Risk 75
First published (updated )

Ivanti Ivanti Endpoint ManagerIvanti Endpoint Manager AuthHelper Authentication Bypass Vulnerability

Risk 75
First published (updated )
Advisory
ZDI-26-080
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Ivanti Endpoint ManagerIvanti Endpoint Manager ROI SQL Injection Remote Code Execution Vulnerability

Risk 51
First published (updated )
Advisory
ZDI-26-079

Ivanti Endpoint ManagerZDI-26-079: Ivanti Endpoint Manager ROI SQL Injection Remote Code Execution Vulnerability

Risk 46
First published (updated )

Ivanti Endpoint ManagerIvanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

Risk 65
Severity
8.6
First published (updated )

Ivanti Endpoint ManagerSQL Injection

Risk 38
Severity
6.5
First published (updated )

The RegisterJanuary blues return as Ivanti coughs up exploited EPMM zero-days

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203