Ivanti vulnerabilities under active exploitation
14 CVEs on this page carry evidence of exploitation.
Which Ivanti vulnerabilities are being exploited?
13 of them are in the CISA KEV catalog.
One was added to KEV in the last 90 days.
- CVE-2026-21962 In KEV since 2026-08-24 · EPSS 71% · No fix identified here
- CVE-2026-6973 In KEV since 2026-05-07 · No fix identified here
- CVE-2026-1340 In KEV since 2026-04-08 · EPSS 99% · No fix identified here
- CVE-2026-20127 In KEV since 2026-02-25 · EPSS 88% · Fix identified
- CVE-2026-1281 In KEV since 2026-01-29 · EPSS 99% · Fix identified
- CVE-2026-24061 In KEV since 2026-01-26 · EPSS 99% · No fix identified here
- CVE-2025-0282 In KEV since 2025-01-08 · EPSS 100.0% · Used in ransomware · Fix identified
- CVE-2024-21762 In KEV since 2024-02-09 · EPSS 83% · Used in ransomware · No fix identified here
- CVE-2024-21887 In KEV since 2024-01-10 · EPSS 100.0% · Used in ransomware · No fix identified here
- CVE-2023-46805 In KEV since 2024-01-10 · EPSS 100.0% · Used in ransomware · No fix identified here
- CVE-2023-27997 In KEV since 2023-06-13 · EPSS 86% · Used in ransomware · No fix identified here
- CVE-2022-42475 In KEV since 2022-12-13 · EPSS 99% · Used in ransomware · No fix identified here
- CVE-2020-1938 In KEV since 2022-03-03 · EPSS 99% · No fix identified here
- CVE-2025-24799 EPSS 87% · No fix identified here
Which of them have a fix?
We can name a fix for 3 of them.
For the rest we hold no patch identifier, which is not the same as no patch existing.
What PlainSec published about Ivanti
Which Ivanti products this page tracks
- Ivanti
- Ivanti Connect Secure
- Ivanti Endpoint Manager (EPM)
- Ivanti Endpoint Manager Mobile (EPMM)
- Pulse Secure
KEV and EPSS are re-checked daily. Page last updated 2026-09-26.