Exploitation timeline
Threadlinqs has recorded 22 Ivanti CVEs published between and . The busiest month was 2024-01 (2 new CVEs). 19 of them (86%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 22 of 22 tracked Ivanti CVEs.
- CVE-2019-11510critical 9.9KEVRansomwareEPSS 100%
- CVE-2026-10520critical 10KEVEPSS 99%
- CVE-2019-11539high 8KEVRansomwareEPSS 98.6%
- CVE-2023-35078critical 9.8KEVRansomwareEPSS 94.5%
- CVE-2024-21887critical 9.1KEVRansomwareEPSS 94.4%
- CVE-2023-46805high 8.2KEVRansomwareEPSS 94.4%
- CVE-2024-8963critical 9.4KEVEPSS 94.2%
- CVE-2025-0282critical 9KEVRansomwareEPSS 94.1%
- CVE-2025-4427medium 5.3KEVEPSS 91.6%
- CVE-2023-35081high 7.2KEVEPSS 91.2%
- CVE-2020-8243high 7.2KEVEPSS 90.8%
- CVE-2026-1281critical 9.8KEVEPSS 71.8%
- CVE-2026-1340critical 9.8KEVEPSS 67.8%
- CVE-2026-1603high 8.6KEVEPSS 54.8%
- CVE-2025-4428high 7.2KEVEPSS 48%
- CVE-2021-22893critical 10KEVRansomwareEPSS 47.2%
- CVE-2021-22894high 8.8KEVEPSS 41.3%
- CVE-2021-22900high 7.2KEVEPSS 14.1%
- CVE-2026-6973high 7.2KEVRansomwareEPSS 4.9%
- CVE-2026-1602medium 6.5EPSS 0.1%
- CVE-2025-10573critical 9.6EPSS 0%
- CVE-2026-18851high 8.8
Products affected
Threadlinqs normalises CPE and CNA product records across all 22 CVEs; 7 distinct Ivanti products are affected. The most frequently affected:
- Connect Secure 9 CVEs
- Endpoint Manager Mobile 8 CVEs
- Policy Secure 4 CVEs
- Endpoint Manager 3 CVEs
- Endpoint Manager Cloud Services Appliance 1 CVE
- Neurons For Zero-trust Access 1 CVE
- Sentry 1 CVE
Threat activity
23 tracked threat campaigns reference Ivanti products or exploit Ivanti CVEs:
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)HIGH
- Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745 Unauthenticated Deserialization RCE, CVE-2026-12645-12647 Missing Authorization RCE, CVE-2026-18851 EPMM Privilege Escalation, CVE-2026-83527 Sentry Auth Bypass)CRITICAL
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec ReferencesCRITICAL
- Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter DevicesHIGH
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote AccessMEDIUM
- CISA BOD 26-04: Risk-Based Vulnerability Remediation and CISO Reporting Mandate for FCEB AgenciesMEDIUM
- ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security ResearchersHIGH
- ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2HIGH
- ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security ResearchersHIGH
- CVE-2026-10520 — Ivanti Sentry Unauthenticated OS Command Injection (Root RCE), added to CISA KEVCRITICAL
- Ivanti Neurons for ITSM CVE-2026-9614 — Improper Access Control Privilege Escalation to AdministratorHIGH
- Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Authenticated RCE Zero-Day — CVE-2026-6973 (CISA KEV, Active Exploitation)HIGH
- The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 Botnet of 1,570+ Corporate Hosts for Double-Extortion OperationsHIGH
- APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic TargetingCRITICAL
- Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)CRITICAL
- BRICKSTORM Backdoor: UNC5221 PRC-Nexus APT Targeting VMware vSphere InfrastructureCRITICAL
- APT41/Silver Dragon Expanding Enterprise Attack Surface — Google Drive C2, AppDomain Hijacking, Cloud/Supply Chain TargetingHIGH
- Ivanti EPMM Unauthenticated RCE via Code Injection — CVE-2026-1281 & CVE-2026-1340 (Sleeper Shells)CRITICAL
- Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential TheftHIGH
- Ivanti Endpoint Manager Pre-Auth Credential Leak via Authentication Bypass (CVE-2026-1603)CRITICAL
- RESURGE Passive Rootkit — Ivanti Connect Secure CVE-2025-0282 Exploitation, CRC32 TLS Fingerprint C2, Covert SSH Channel, SPAWNCHIMERA/SPAWNSLOTH Variants, CISA MAR UpdateCRITICAL
- Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch Government Breached, Bulletproof Hosting IAB, Sleeper Webshells, 28K+ Attacking IPsCRITICAL
- Ivanti EPMM Pre-Auth Remote Code Execution (CVE-2026-1281 / CVE-2026-1340)CRITICAL
Threat actors targeting Ivanti
Named threat actors attributed to campaigns that involve Ivanti products or CVEs, with the number of linked campaigns:
How to prioritise Ivanti patching
This order follows the data Threadlinqs holds for Ivanti, not a generic severity checklist:
- 19 of 22 Ivanti CVEs (86%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2019-11510, CVE-2026-10520, CVE-2019-11539.
- 8 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2026-1602 (0.1%), CVE-2025-10573 (0%).
- 10 CVEs score Critical and 10 High on CVSS v3 (maximum 10, average 8.5); sequence these after KEV and high-EPSS items.
- 7 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.