VPN Concentrators & Endpoint Management5 Active Advisories Tracked

Ivanti Vulnerability & Threat Radar

High-profile VPN bypasses and command injection zero-days affecting Ivanti Connect Secure and Policy Secure gateways.

Recommended Protective Controls for Ivanti Environments

Deploy continuous behavioral telemetry and micro-segmentation boundaries to shield Ivanti assets.

Evaluate Recommended Defenses →

Recent Disclosures & Advisories

5 Critical Severity
CISA KEV
6/11/2026

Ivanti Sentry OS Command Injection Vulnerability

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This is a critical threat mapped to CVE-2026-10520; security leaders should validate exposure, prioritize patching, and verif...

CISA KEV
5/7/2026

Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains an improper input validation vulnerability that allows a remotely authenticated user with administrative access to achieve remote code execution. This is a critical threat mapped to CVE-2026-6973; security leaders should validate exposure, prioritize patching, and verif...

CISA KEV
4/8/2026

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. This is a critical threat mapped to CVE-2026-1340; security leaders should validate exposure, prioritize patching, and verify compensating controls.

CISA KEV
3/9/2026

Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability

Ivanti Endpoint Manager (EPM) contains an authentication bypass using an alternate path or channel vulnerability that could allow a remote unauthenticated attacker to leak specific stored credential data. This is a critical threat mapped to CVE-2026-1603; security leaders should validate exposure, prioritize patchin...

CISA KEV
1/29/2026

Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability

Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability that could allow attackers to achieve unauthenticated remote code execution. This is a critical threat mapped to CVE-2026-1281; security leaders should validate exposure, prioritize patching, and verify compensating controls.

Share Intel:Share on XLinkedIn

Never Miss a Critical Ivanti Patch

Subscribe to the SecOps Pulse executive threat briefing for early warnings on unpatched vulnerabilities.

Weekly Executive Briefing

Top critical & high-severity threats, every week.

No spam. Unsubscribe anytime. SecOpsPulse may include sponsored security tool recommendations.