Ivanti Vulnerabilities and Affected Products
Vulnerabilities associated with Endpoint Manager.
Products
Clear product- Avalanche94 vulnerabilities
- Endpoint Manager71 vulnerabilities
- Connect Secure62 vulnerabilities
- Policy Secure52 vulnerabilities
- endpoint_manager45 vulnerabilities
- EPM33 vulnerabilities
- connect_secure24 vulnerabilities
- policy_secure20 vulnerabilities
- Endpoint Manager Mobile18 vulnerabilities
- Secure Access Client15 vulnerabilities
- ZTA Gateway15 vulnerabilities
- Connect Secure and Policy Secure14 vulnerabilities
- Neurons for Secure Access13 vulnerabilities
- EPMM11 vulnerabilities
- Workspace Control10 vulnerabilities
- automation8 vulnerabilities
- endpoint_manager_mobile8 vulnerabilities
- Endpoint Manager Mobile (EPMM)7 vulnerabilities
- Pulse Connect Secure7 vulnerabilities
- CSA (Cloud Services Appliance)6 vulnerabilities
- endpoint_manager_cloud_services_appliance6 vulnerabilities
- secure_access_client6 vulnerabilities
- Sentry6 vulnerabilities
- Cloud Services Application5 vulnerabilities
- Endpoint Manager (EPM)5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-18129HIGH | Generated title:Ivanti Endpoint Manager Core Cleartext Transmission of Sensitive InformationCleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections. CWE-295Aug 11, 2026 | CVSS8.1v3.1 | EPSS0.871% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-18127HIGH | Generated title:Ivanti Endpoint Manager Core External Control of Filename Leading to S3 Bucket Write ControlExternal control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage. CWE-73Aug 11, 2026 | CVSS7.7v3.1 | EPSS0.392% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-18125HIGH | Generated title:Ivanti Endpoint Manager Agent Out-of-Bounds Read Denial of Service VulnerabilityAn out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service. CWE-125Aug 11, 2026 | CVSS7.5v3.1 | EPSS0.775% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8111HIGH | Generated title:Ivanti Endpoint Manager SQL Injection in Web ConsoleSQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution. CWE-89May 12, 2026 | CVSS8.8v3.1 | EPSS0.883% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8110HIGH | Generated title:Ivanti Endpoint Manager Incorrect Permission Assignment Privilege EscalationIncorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges. CWE-732May 12, 2026 | CVSS7.8v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-8109MEDIUM | Generated title:Ivanti Endpoint Manager Core Server Exposed Dangerous Method Leading to Credential DisclosureAn exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials. CWE-749May 12, 2026 | CVSS6.5v3.1 | EPSS0.701% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-1603HIGH | Ivanti Endpoint Manager (EPM) Authentication Bypass VulnerabilityAn authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data. | CVSS8.6v3.1 | EPSS80.6% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2026-1602MEDIUM | Generated title:Potential SQL Injection in Ivanti Endpoint ManagerSQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Feb 10, 2026 | CVSS6.5v3.1 | EPSS0.685% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13662HIGH | Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required. CWE-347Dec 9, 2025 | CVSS7.8v3.1 | EPSS0.563% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13661HIGH | Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required. CWE-22Dec 9, 2025 | CVSS7.1v3.1 | EPSS1.33% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-13659HIGH | Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required. CWE-913Dec 9, 2025 | CVSS8.8v3.1 | EPSS1.91% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-10573CRITICAL | Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required. CWE-79Dec 9, 2025 | CVSS9.6v3.1 | EPSS33.5% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-10918HIGH | Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk CWE-276Nov 11, 2025 | CVSS7.1v3.1 | EPSS0.239% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62384MEDIUM | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Oct 13, 2025 | CVSS6.5v3.1 | EPSS0.774% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62386MEDIUM | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Oct 13, 2025 | CVSS6.5v3.1 | EPSS0.768% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62383MEDIUM | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Oct 13, 2025 | CVSS6.5v3.1 | EPSS0.774% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62391MEDIUM | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Oct 13, 2025 | CVSS6.5v3.1 | EPSS0.768% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62385MEDIUM | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Oct 13, 2025 | CVSS6.5v3.1 | EPSS0.768% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62387MEDIUM | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Oct 13, 2025 | CVSS6.5v3.1 | EPSS1.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62388MEDIUM | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Oct 13, 2025 | CVSS6.5v3.1 | EPSS0.769% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62389MEDIUM | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Oct 13, 2025 | CVSS6.5v3.1 | EPSS1.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62390MEDIUM | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Oct 13, 2025 | CVSS6.5v3.1 | EPSS1.62% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-62392MEDIUM | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Oct 13, 2025 | CVSS6.5v3.1 | EPSS0.769% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-11623MEDIUM | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. CWE-89Oct 13, 2025 | CVSS6.5v3.1 | EPSS0.775% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-9713HIGH | Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. CWE-22Oct 13, 2025 | CVSS8.8v3.1 | EPSS14.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |