ivanti security advisories
7 threat alerts tracking vulnerabilities and security advisories that affect ivanti products.
Vulnios monitors ivanti CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent ivanti security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2021-22893 — ivanti — connect_secure
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect S
criticalCVE-2021-22893Critical Vulnerability: CVE-2023-35078 — ivanti — endpoint_manager_mobile
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
criticalCVE-2023-35078Critical Vulnerability: CVE-2021-44529 — ivanti — endpoint_manager_cloud_services_appliance
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
criticalCVE-2021-44529Critical Vulnerability: CVE-2025-0282 — ivanti — connect_secure, neurons_for_zero-trust_access
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remot
criticalCVE-2025-0282Critical Vulnerability: CVE-2025-22457 — ivanti — connect_secure, policy_secure
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenti
criticalCVE-2025-22457Critical Vulnerability: CVE-2024-7593 — ivanti — virtual_traffic_manager
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
criticalCVE-2024-7593Critical Vulnerability: CVE-2016-3147 — ivanti — landesk_management_suite
Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a larg
criticalCVE-2016-3147
Track ivanti exposure across your environment
Vulnios automatically cross-references your asset inventory against new ivanti CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan