Ivanti vulnerabilities under active exploitation
14 CVEs on this page carry evidence of exploitation.
Which Ivanti vulnerabilities are being exploited?
12 of them are in the CISA KEV catalog.
- CVE-2026-6973 In KEV since 2026-05-07 · No fix identified here
- CVE-2026-1340 In KEV since 2026-04-08 · EPSS 84% · No fix identified here
- CVE-2026-20127 In KEV since 2026-02-25 · EPSS 88% · Fix identified
- CVE-2026-1281 In KEV since 2026-01-29 · EPSS 82% · Fix identified
- CVE-2026-24061 In KEV since 2026-01-26 · EPSS 98% · No fix identified here
- CVE-2025-0282 In KEV since 2025-01-08 · EPSS 100.0% · Used in ransomware · Fix identified
- CVE-2024-21762 In KEV since 2024-02-09 · EPSS 84% · Used in ransomware · No fix identified here
- CVE-2024-21887 In KEV since 2024-01-10 · EPSS 100.0% · Used in ransomware · No fix identified here
- CVE-2023-46805 In KEV since 2024-01-10 · EPSS 100.0% · Used in ransomware · No fix identified here
- CVE-2023-27997 In KEV since 2023-06-13 · EPSS 86% · Used in ransomware · No fix identified here
- CVE-2022-42475 In KEV since 2022-12-13 · EPSS 99% · Used in ransomware · No fix identified here
- CVE-2020-1938 In KEV since 2022-03-03 · EPSS 99% · No fix identified here
- CVE-2025-24799 EPSS 86% · No fix identified here
- CVE-2026-21962 EPSS 43% · No fix identified here
Which of them have a fix?
We can name a fix for 3 of them.
For the rest we hold no patch identifier, which is not the same as no patch existing.
What PlainSec published about Ivanti
Which Ivanti products this page tracks
- Ivanti
- Ivanti Connect Secure
- Ivanti Endpoint Manager (EPM)
- Ivanti Endpoint Manager Mobile (EPMM)
- Pulse Secure
KEV and EPSS are re-checked daily. Page last updated 2026-08-16.