Ivanti Security Advisories & CVEs
44 advisories tracked · Ivanti Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Ivanti CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Ivanti device is affected
Pick your product and enter the exact software release it runs. We match it against the affected/fixed versions in Ivanti's recent advisories.
Official source
Ivanti Security Advisories
Polled via Ivanti's official Security Advisory blog RSS. Posts summarize each monthly/out-of-band advisory and link to the canonical Ivanti Security Advisory KB. Ivanti Connect Secure, Policy Secure and EPMM are frequent, high-priority exploitation targets.
Latest Ivanti advisories
High [CVE-2026-18129] Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.
High [CVE-2026-18127] External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
High August 2026 Security Update
Ivanti releases standard security patches on the second Tuesday of every month. In today’s rapidly evolving technology and threat landscape, we believe responsible transparency should be a cornerstone of any product security program. AI is compressing the time-to-exploit, and Ivanti uses leading technologies to proactively find and fix issues ––including integrating advanced LLMs into our Engineering and product security to enhance the capabilities of our teams. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Neurons for MDM and Endpoint Manager (EPM). It is important for customers to know: - We have no evidence of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in the Security Advisories: How AI will affect vulnerability disclosures in our products
High [CVE-2026-18125] out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
High [CVE-2026-14903] Path traversal in Ivanti Xtraction before version 2026.2.1
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
High July 2026 Security Update
Ivanti releases standard security patches on the second Tuesday of every month. In today’s rapidly evolving technology and threat landscape, we believe responsible transparency should be a cornerstone of any product security program. AI is compressing the time-to-exploit, and Ivanti uses leading technologies to proactively find and fix issues ––including integrating advanced LLMs into our Engineering and product security to enhance the capabilities of our teams. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Xtraction. It is important for customers to know: - We have no evidence of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in the Security Advisories: How AI will affect vulnerability disclosures in our products
Medium [CVE-2026-14902] open redirect in Ivanti Xtraction before version 2026.2.1
An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.
Critical [CVE-2026-10523] Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
Critical [CVE-2026-10520] OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
High [CVE-2026-10727] OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions
An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root
High June 2026 Security Update
Ivanti releases standard security patches on the second Tuesday of every month. In today’s rapidly evolving technology and threat landscape, we believe responsible transparency should be a cornerstone of any product security program. AI is compressing the time-to-exploit, and Ivanti uses leading technologies to proactively find and fix issues ––including integrating advanced LLMs into our Engineering and product security to enhance the capabilities of our teams. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM) and Ivanti Sentry. It is important for customers to know: - We have no evidence of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in the Security Advisories:
High [CVE-2026-9614] Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises)
An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.
High June 2026 Ivanti Neurons for ITSM Security Update
In today’s rapidly evolving technology and threat landscape, responsible transparency should be a cornerstone of any product security program. As part of our ongoing product security program, we continually assess, investigate, and address vulnerabilities. When an issue is found, we communicate relevant information as quickly and responsibly as possible. To this end, we are issuing an important security update addressing vulnerabilities in Ivanti Neurons for ITSM (cloud and on-premises). Customers should review the Security Advisory for more information and version specific details. Customers using the on-premises Ivanti Neurons for ITSM solution should review the Security advisory and apply fix as soon as possible. At the time of this publication, we are not aware of any customers being exploited through the vulnerability disclosed today. Our top priority is the security of our customers and believe the increase in identified, resolved, and transparently communicated vulnerabilities demonstrates that commitment. Customers and partners with questions about their environment or remediation steps can contact Ivanti Support. Cases can be logged via the Ivanti Innovators Hub (login credentials required). Want to stay up to date on Ivanti Security Advisories? Paste into your preferred RSS reader / functionality in your email program.
High [CVE-2026-8992] improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6
An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.
High [CVE-2026-8111] SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.
High [CVE-2026-8110] Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6
Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.
High [CVE-2026-7432] race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
High May 2026 Security Update
Ivanti releases standard security patches on the second Tuesday of every month. In today’s rapidly evolving technology and threat landscape, we believe responsible transparency should be a cornerstone of any product security program. AI is compressing the time-to-exploit, and Ivanti uses leading technologies to proactively find and fix issues ––including integrating advanced LLMs into our Engineering and product security to enhance the capabilities of our teams. Our philosophy is simple: discovering and communicating vulnerabilities, and sharing that information with defenders, is not an indication of weakness; rather it is evidence of rigorous scrutiny and a proactive vulnerability management program. By aggressively seeking to identify and address vulnerabilities, our aim is to get ahead of threat actors to ensure our customers can take the steps needed to protect their environments. To that end, today Ivanti is disclosing vulnerabilities in Ivanti Secure Access Client, Xtraction, Virtual Traffic Manager and Endpoint Manager (EPM). It is important for customers to know: - We have no evidence of these vulnerabilities being exploited in the wild. - These vulnerabilities do not impact any other Ivanti solutions. More information on these vulnerabilities and detailed instructions on how to remediate the issues can be found in the Security Advisories:
Medium [CVE-2026-8109] exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
Medium [CVE-2026-7431] incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6
An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.