Cross-Vendor Patch Advisories

Every vendor except Microsoft: CISA KEV advisories scored on the EVULNABLE Risk scale, Linux distribution advisories, and vendor security bulletins.

Browse Advisories

Association
Vendor — all

Leave every box clear to show all 282 vendors.

35 of 1,308 advisories match the current filters, sorted by EVULNABLE Risk.

CISA KEV advisories matching the current filters, ranked by EVULNABLE Risk Score
CVE Vendor Product Vulnerability EVRS EPSS Ransomware CISA due
CVE-2025-22457 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability 95 Immediate 0.999 (99.98th pctl) Known 2025-04-11
CVE-2019-11510 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability 94 Immediate 0.999 (99.99th pctl) Known 2022-05-03
CVE-2023-35078 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability 94 Immediate 0.999 (99.99th pctl) Known 2023-08-15
CVE-2023-35082 Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability 94 Immediate 0.999 (99.99th pctl) Known 2024-02-08
CVE-2025-0282 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability 94 Immediate 0.999 (99.98th pctl) Known 2025-01-15
CVE-2023-38035 Ivanti Sentry Ivanti Sentry Authentication Bypass Vulnerability 94 Immediate 0.999 (99.97th pctl) Known 2023-09-12
CVE-2024-21887 Ivanti Connect Secure and Policy Secure Ivanti Connect Secure and Policy Secure Command Injection Vulnerability 93 Immediate 0.999 (99.99th pctl) Known 2024-01-22
CVE-2021-44529 Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability 93 Immediate 0.991 (99.93rd pctl) Known 2024-04-15
CVE-2024-21893 Ivanti Connect Secure, Policy Secure, and Neurons Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability 92 Immediate 0.999 (99.99th pctl) Known 2024-02-02
CVE-2023-46805 Ivanti Connect Secure and Policy Secure Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability 92 Immediate 0.999 (99.98th pctl) Known 2024-01-22
CVE-2026-10520 Ivanti Sentry Ivanti Sentry OS Command Injection Vulnerability 92 Immediate 0.999 (99.97th pctl) Unknown/None 2026-06-14
CVE-2019-11539 Ivanti Pulse Connect Secure and Pulse Policy Secure Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability 90 Immediate 0.985 (99.92nd pctl) Known 2022-05-03
CVE-2024-7593 Ivanti Virtual Traffic Manager Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability 88 Immediate 0.999 (99.98th pctl) Unknown/None 2024-10-15
CVE-2024-29824 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability 87 Immediate 0.999 (99.97th pctl) Unknown/None 2024-10-23
CVE-2020-15505 Ivanti MobileIron Multiple Products Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability 87 Immediate 0.997 (99.95th pctl) Unknown/None 2022-05-03
CVE-2024-8963 Ivanti Cloud Services Appliance (CSA) Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability 87 Immediate 0.986 (99.92nd pctl) Unknown/None 2024-10-10
CVE-2026-1340 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability 86 Immediate 0.862 (99.72nd pctl) Unknown/None 2026-04-11
CVE-2024-13159 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability 85 Immediate 0.999 (99.99th pctl) Unknown/None 2025-03-31
CVE-2025-4427 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability 85 Immediate 0.999 (99.97th pctl) Unknown/None 2025-06-09
CVE-2026-1281 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability 85 Immediate 0.818 (99.62nd pctl) Unknown/None 2026-02-01
CVE-2021-22893 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Use-After-Free Vulnerability 85 Immediate 0.472 (98.8th pctl) Known 2022-05-03
CVE-2020-8260 Ivanti Pulse Connect Secure Ivanti Pulse Connect Secure Code Execution Vulnerability 83 Urgent 0.965 (99.88th pctl) Unknown/None 2022-05-03
CVE-2024-13160 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability 83 Urgent 0.912 (99.8th pctl) Unknown/None 2025-03-31
CVE-2025-4428 Ivanti Endpoint Manager Mobile (EPMM) Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability 83 Urgent 0.862 (99.72nd pctl) Unknown/None 2025-06-09
CVE-2024-13161 Ivanti Endpoint Manager (EPM) Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability 82 Urgent 0.901 (99.79th pctl) Unknown/None 2025-03-31
Download filtered advisories (CSV)

Exactly the 35 advisory(ies) matching the filters above.

Advisory detail

Expand any advisory for its description, CISA's own required action, and research links.

CVE-2025-22457 — Ivanti Connect Secure, Policy Secure, and ZTA Gateways: Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

EVULNABLE Risk · priority 95/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations as set forth in the CISA instructions linked below.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-04-04

CISA remediation due: 2025-04-11

Known ransomware campaign use: Known

CVE-2019-11510 — Ivanti Pulse Connect Secure: Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability

Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Known

CVE-2023-35078 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-07-25

CISA remediation due: 2023-08-15

Known ransomware campaign use: Known

CVE-2023-35082 — Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core: Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-18

CISA remediation due: 2024-02-08

Known ransomware campaign use: Known

CVE-2025-0282 — Ivanti Connect Secure, Policy Secure, and ZTA Gateways: Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations as set forth in the CISA instructions linked below to include conducting hunt activities, taking remediation actions if applicable, and applying updates prior to returning a device to service.

CVSS: 9.0 (NVD)

FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-01-08

CISA remediation due: 2025-01-15

Known ransomware campaign use: Known

CVE-2023-38035 — Ivanti Sentry: Ivanti Sentry Authentication Bypass Vulnerability

Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

EVULNABLE Risk · priority 94/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2023-08-22

CISA remediation due: 2023-09-12

Known ransomware campaign use: Known

CVE-2024-21887 — Ivanti Connect Secure and Policy Secure: Ivanti Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-10

CISA remediation due: 2024-01-22

Known ransomware campaign use: Known

CVE-2021-44529 — Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA): Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability

Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).

EVULNABLE Risk · priority 93/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.991.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.991 (99.93rd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-03-25

CISA remediation due: 2024-04-15

Known ransomware campaign use: Known

CVE-2024-21893 — Ivanti Connect Secure, Policy Secure, and Neurons: Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.

EVULNABLE Risk · priority 92/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.2 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-31

CISA remediation due: 2024-02-02

Known ransomware campaign use: Known

CVE-2023-46805 — Ivanti Connect Secure and Policy Secure: Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.

EVULNABLE Risk · priority 92/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.2 (NVD)

FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-01-10

CISA remediation due: 2024-01-22

Known ransomware campaign use: Known

CVE-2026-10520 — Ivanti Sentry: Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

EVULNABLE Risk · priority 92/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-06-11

CISA remediation due: 2026-06-14

Known ransomware campaign use: Unknown/None

CVE-2019-11539 — Ivanti Pulse Connect Secure and Pulse Policy Secure: Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability

Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.

EVULNABLE Risk · priority 90/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.985.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.985 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Known

CVE-2024-7593 — Ivanti Virtual Traffic Manager: Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.

EVULNABLE Risk · priority 88/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.999 (99.98th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-09-24

CISA remediation due: 2024-10-15

Known ransomware campaign use: Unknown/None

CVE-2024-29824 — Ivanti Endpoint Manager (EPM): Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability

Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code.

EVULNABLE Risk · priority 87/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-10-02

CISA remediation due: 2024-10-23

Known ransomware campaign use: Unknown/None

CVE-2020-15505 — Ivanti MobileIron Multiple Products: Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.

EVULNABLE Risk · priority 87/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.997.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.997 (99.95th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2024-8963 — Ivanti Cloud Services Appliance (CSA): Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance.

EVULNABLE Risk · priority 87/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.986.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: As Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.

CVSS: 9.1 (NVD)

FIRST EPSS: 0.986 (99.92nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2024-09-19

CISA remediation due: 2024-10-10

Known ransomware campaign use: Unknown/None

CVE-2026-1340 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

EVULNABLE Risk · priority 86/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.862.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.862 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-04-08

CISA remediation due: 2026-04-11

Known ransomware campaign use: Unknown/None

CVE-2024-13159 — Ivanti Endpoint Manager (EPM): Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.999 (99.99th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-10

CISA remediation due: 2025-03-31

Known ransomware campaign use: Unknown/None

CVE-2025-4427 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted API requests. This vulnerability results from an insecure implementation of the Spring Framework open-source library.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.999.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.999 (99.97th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-05-19

CISA remediation due: 2025-06-09

Known ransomware campaign use: Unknown/None

CVE-2026-1281 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution.

EVULNABLE Risk · priority 85/100 Immediate Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch Immediately

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.818.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 9.8 (NVD)

FIRST EPSS: 0.818 (99.62nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2026-01-29

CISA remediation due: 2026-02-01

Known ransomware campaign use: Unknown/None

CVE-2021-22893 — Ivanti Pulse Connect Secure: Ivanti Pulse Connect Secure Use-After-Free Vulnerability

Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.

EVULNABLE Risk · priority 85/100 Immediate Raised to the floor for a confirmed exploited vulnerability. Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Out-of-Band / Urgent Remediation

Why this score: Listed in the CISA KEV catalog, and Confirmed exploitation in the wild.

Exigent: CISA KEV-listed, confirmed actively exploited, a real published CVSS ≥ 9.0, and a genuine urgency signal — all at once.

CISA required action: Apply updates per vendor instructions.

CVSS: 10.0 (NVD)

FIRST EPSS: 0.472 (98.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Known

CVE-2020-8260 — Ivanti Pulse Connect Secure: Ivanti Pulse Connect Secure Code Execution Vulnerability

Pulse Connect Secure contains an unspecified vulnerability that allows an authenticated attacker to perform code execution using uncontrolled gzip extraction.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.965.

CISA required action: Apply updates per vendor instructions.

CVSS: 7.2 (NVD)

FIRST EPSS: 0.965 (99.88th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2021-11-03

CISA remediation due: 2022-05-03

Known ransomware campaign use: Unknown/None

CVE-2024-13160 — Ivanti Endpoint Manager (EPM): Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.912.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.912 (99.8th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-10

CISA remediation due: 2025-03-31

Known ransomware campaign use: Unknown/None

CVE-2025-4428 — Ivanti Endpoint Manager Mobile (EPMM): Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. This vulnerability results from an insecure implementation of the Hibernate Validator open-source library, as represented by CVE-2025-35036.

EVULNABLE Risk · priority 83/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.862.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 8.8 (NVD)

FIRST EPSS: 0.862 (99.72nd pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-05-19

CISA remediation due: 2025-06-09

Known ransomware campaign use: Unknown/None

CVE-2024-13161 — Ivanti Endpoint Manager (EPM): Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability

Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.

EVULNABLE Risk · priority 82/100 Urgent Intelligence coverage 75/90 — no pre-patch disclosure data

Recommended priority: Patch This Cycle

Why this score: Listed in the CISA KEV catalog, and an EPSS probability of 0.901.

CISA required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS: 7.5 (NVD)

FIRST EPSS: 0.901 (99.79th pctl) — probability of exploitation in the next 30 days, with its rank across all scored CVEs

CISA added: 2025-03-10

CISA remediation due: 2025-03-31

Known ransomware campaign use: Unknown/None

Data sources & attribution

Known-exploitation status, required actions, ransomware association and remediation deadlines come from the CISA Known Exploited Vulnerabilities Catalog. Exploitation probability and percentile are provided by FIRST.org's EPSS, used under FIRST's open data terms.

Microsoft Patch Tuesday data is sourced from the Microsoft Security Update Guide; lifecycle milestones from endoflife.date. Linux distribution advisories come from Red Hat, Ubuntu and Debian; vendor bulletins from Adobe, Apple, Chrome, Cisco, Ivanti and Oracle, each linked to its own advisory.