Where
-Infinity
0

Vendor Risk Score

See how ivanti compares to other vendors in security performance

View Risk Score →

Software

Ivanti Secure AccessInput validation error in Secure Access clients prior to 14.55

Risk 20
Severity
2.3
First published (updated )

Ivanti XtractionPath Traversal

Risk 44
Severity
7.7
First published (updated )

Ivanti XtractionAn open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacke…

Risk 22
Severity
4
First published (updated )

5 enterprise CVEs from last week worth checking out this week (Jun 7–13)

First published (updated )
Social
reddit

BleepingComputerCISA orders feds to patch actively exploited Ivanti flaw by Sunday

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Dark ReadingMax-Severity Ivanti Flaw Exploited 24 Hours After Disclosure

First published (updated )

BleepingComputerCISA tells govt agencies to patch critical exploited flaws in 3 days

First published (updated )

BleepingComputerMax severity Ivanti Sentry vulnerability now exploited in attacks

First published (updated )

BleepingComputerIvanti: Max severity Sentry flaw allows code execution as root

First published (updated )

More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs

First published (updated )
Social
reddit
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs

First published (updated )
Social
reddit

Ivanti EPMMOS Command Injection, Command Injection

Risk 66
Severity
7.2
First published (updated )

Ivanti Standalone SentryAn Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R1…

Risk 88
Severity
9.9
First published (updated )

Ivanti Standalone SentryIvanti Sentry OS Command Injection Vulnerability

Risk 100
Severity
10
3 Months
First published (updated )

Ivanti Ivanti Neurons for ITSMAn Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a…

Risk 57
Severity
8.8
EPSS
1.44%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Ivanti Secure Access ClientAn improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows…

Risk 56
Severity
8.8
EPSS
0.56%
First published (updated )

Ivanti Endpoint ManagerSQL Injection

Risk 56
Severity
8.8
EPSS
0.35%
First published (updated )

Ivanti Endpoint ManagerIncorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 all…

Risk 51
Severity
7.8
EPSS
0.03%
First published (updated )

Ivanti Endpoint ManagerAn exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 al…

Risk 27
Severity
6.5
EPSS
0.12%
First published (updated )

Ivanti Virtual Traffic ManagerOS Command Injection, Command Injection

Risk 50
Severity
7.2
EPSS
1.46%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Ivanti Secure Access ClientRace Condition

Risk 51
Severity
7.8
EPSS
0.03%
First published (updated )

Ivanti Secure Access ClientAn incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.…

Risk 21
Severity
4.4
EPSS
0.04%
First published (updated )

Ivanti XtractionExternal control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authentica…

Risk 49
Severity
9.6
EPSS
0.12%
First published (updated )

Ivanti Endpoint ManagerIvanti Endpoint Manager RemoteControlAuth Exposed Dangerous Method Information Disclosure Vulnerability

Risk 43
First published (updated )
Advisory
ZDI-26-308

Ivanti Endpoint ManagerZDI-26-308: Ivanti Endpoint Manager RemoteControlAuth Exposed Dangerous Method Information Disclosure Vulnerability

Risk 48
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

BleepingComputerCISA gives feds four days to patch Ivanti flaw exploited as zero-day

First published (updated )

BleepingComputerCISA gives feds four days to patch Ivanti flaw exploited as zero-day

First published (updated )

Ivanti Endpoint Manager MobileAn Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 a…

Risk 69
Severity
9.1
First published (updated )

Ivanti Endpoint Manager MobileAn Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a …

Risk 89
Severity
9.8
First published (updated )

Ivanti Endpoint Manager MobileImproper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allo…

Risk 48
Severity
9.1
EPSS
0.06%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203