# Ivanti vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 22 Ivanti CVEs, 19 in the CISA Known Exploited Vulnerabilities catalog, 8 used in ransomware campaigns, linked to 23 tracked threat campaigns and 8 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 22 Ivanti CVEs published between 2019-04-15 and 2026-09-15. The busiest month was 2024-01 (2 new CVEs). 19 of them (86%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 22 of 22 tracked Ivanti CVEs.

- [CVE-2019-11510](https://intel.threadlinqs.com/cve/CVE-2019-11510) — CRITICAL 9.9 · KEV · Ransomware · EPSS 100% · 2019-05-08
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520) — CRITICAL 10 · KEV · EPSS 99% · 2026-06-09
- [CVE-2019-11539](https://intel.threadlinqs.com/cve/CVE-2019-11539) — HIGH 8 · KEV · Ransomware · EPSS 98.6% · 2019-04-26
- [CVE-2023-35078](https://intel.threadlinqs.com/cve/CVE-2023-35078) — CRITICAL 9.8 · KEV · Ransomware · EPSS 94.5% · 2023-07-25
- [CVE-2024-21887](https://intel.threadlinqs.com/cve/CVE-2024-21887) — CRITICAL 9.1 · KEV · Ransomware · EPSS 94.4% · 2024-01-12
- [CVE-2023-46805](https://intel.threadlinqs.com/cve/CVE-2023-46805) — HIGH 8.2 · KEV · Ransomware · EPSS 94.4% · 2024-01-12
- [CVE-2024-8963](https://intel.threadlinqs.com/cve/CVE-2024-8963) — CRITICAL 9.4 · KEV · EPSS 94.2% · 2024-09-19
- [CVE-2025-0282](https://intel.threadlinqs.com/cve/CVE-2025-0282) — CRITICAL 9 · KEV · Ransomware · EPSS 94.1% · 2025-01-08
- [CVE-2025-4427](https://intel.threadlinqs.com/cve/CVE-2025-4427) — MEDIUM 5.3 · KEV · EPSS 91.6% · 2025-05-13
- [CVE-2023-35081](https://intel.threadlinqs.com/cve/CVE-2023-35081) — HIGH 7.2 · KEV · EPSS 91.2% · 2023-08-03
- [CVE-2020-8243](https://intel.threadlinqs.com/cve/CVE-2020-8243) — HIGH 7.2 · KEV · EPSS 90.8% · 2020-09-29
- [CVE-2026-1281](https://intel.threadlinqs.com/cve/CVE-2026-1281) — CRITICAL 9.8 · KEV · EPSS 71.8% · 2026-01-29
- [CVE-2026-1340](https://intel.threadlinqs.com/cve/CVE-2026-1340) — CRITICAL 9.8 · KEV · EPSS 67.8% · 2026-01-29
- [CVE-2026-1603](https://intel.threadlinqs.com/cve/CVE-2026-1603) — HIGH 8.6 · KEV · EPSS 54.8% · 2026-02-10
- [CVE-2025-4428](https://intel.threadlinqs.com/cve/CVE-2025-4428) — HIGH 7.2 · KEV · EPSS 48% · 2025-05-13
- [CVE-2021-22893](https://intel.threadlinqs.com/cve/CVE-2021-22893) — CRITICAL 10 · KEV · Ransomware · EPSS 47.2% · 2021-04-23
- [CVE-2021-22894](https://intel.threadlinqs.com/cve/CVE-2021-22894) — HIGH 8.8 · KEV · EPSS 41.3% · 2021-05-27
- [CVE-2021-22900](https://intel.threadlinqs.com/cve/CVE-2021-22900) — HIGH 7.2 · KEV · EPSS 14.1% · 2021-05-27
- [CVE-2026-6973](https://intel.threadlinqs.com/cve/CVE-2026-6973) — HIGH 7.2 · KEV · Ransomware · EPSS 4.9% · 2026-05-07
- [CVE-2026-1602](https://intel.threadlinqs.com/cve/CVE-2026-1602) — MEDIUM 6.5 · EPSS 0.1% · 2026-02-10
- [CVE-2025-10573](https://intel.threadlinqs.com/cve/CVE-2025-10573) — CRITICAL 9.6 · EPSS 0% · 2025-12-09
- [CVE-2026-18851](https://intel.threadlinqs.com/cve/CVE-2026-18851) — HIGH 8.8 · 2026-09-08

## Products affected

Threadlinqs normalises CPE and CNA product records across all 22 CVEs; 7 distinct Ivanti products are affected. The most frequently affected:

- Connect Secure — 9 CVEs
- Endpoint Manager Mobile — 8 CVEs
- Policy Secure — 4 CVEs
- Endpoint Manager — 3 CVEs
- Endpoint Manager Cloud Services Appliance — 1 CVE
- Neurons For Zero-trust Access — 1 CVE
- Sentry — 1 CVE

## Threat activity

23 tracked threat campaigns reference Ivanti products or exploit Ivanti CVEs:

- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)](https://intel.threadlinqs.com/threat/TL-2026-2649) — HIGH — 2026-09-25
- [Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745 Unauthenticated Deserialization RCE, CVE-2026-12645-12647 Missing Authorization RCE, CVE-2026-18851 EPMM Privilege Escalation, CVE-2026-83527 Sentry Auth Bypass)](https://intel.threadlinqs.com/threat/TL-2026-2396) — CRITICAL — 2026-09-08
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References](https://intel.threadlinqs.com/threat/TL-2026-2364) — CRITICAL — 2026-09-06
- [Edge Infrastructure Under Siege: Tenable and SentinelOne Datasets Reveal Convergent Nation-State and Criminal Exploitation of Perimeter Devices](https://intel.threadlinqs.com/threat/TL-2026-2153) — HIGH — 2026-08-26
- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — MEDIUM — 2026-07-27
- [CISA BOD 26-04: Risk-Based Vulnerability Remediation and CISO Reporting Mandate for FCEB Agencies](https://intel.threadlinqs.com/threat/TL-2026-1134) — MEDIUM — 2026-07-06
- [ChocoPoC RAT Campaign Uses Malicious PoC-Exploit Python Packages to Backdoor Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1062) — HIGH — 2026-07-02
- [ChocoPoC Campaign: Trojanised PoC Exploits and PyPI Packages Deliver Python RAT Using Mapbox Datasets API as Dead-Drop C2](https://intel.threadlinqs.com/threat/TL-2026-1088) — HIGH — 2026-07-02
- [ChocoPoC: Python RAT Distributed via Trojanized PoC Exploits Targeting Security Researchers](https://intel.threadlinqs.com/threat/TL-2026-1125) — HIGH — 2026-07-01
- [CVE-2026-10520 — Ivanti Sentry Unauthenticated OS Command Injection (Root RCE), added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-0793) — CRITICAL — 2026-06-14
- [Ivanti Neurons for ITSM CVE-2026-9614 — Improper Access Control Privilege Escalation to Administrator](https://intel.threadlinqs.com/threat/TL-2026-0676) — HIGH — 2026-06-03
- [Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Authenticated RCE Zero-Day — CVE-2026-6973 (CISA KEV, Active Exploitation)](https://intel.threadlinqs.com/threat/TL-2026-0477) — HIGH — 2026-05-07
- [The Gentlemen Ransomware Operationalizes SystemBC SOCKS5 Botnet of 1,570+ Corporate Hosts for Double-Extortion Operations](https://intel.threadlinqs.com/threat/TL-2026-0399) — HIGH — 2026-04-20
- [APT35 (Charming Kitten) GCC Pre-Positioning Cyber Reconnaissance Campaign Enabling Kinetic Targeting](https://intel.threadlinqs.com/threat/TL-2026-0339) — CRITICAL — 2026-04-09
- [Storm-1175 Medusa Ransomware Zero-Day Exploitation Campaign (CVE-2026-23760, CVE-2025-10035)](https://intel.threadlinqs.com/threat/TL-2026-0326) — CRITICAL — 2026-04-06
- [BRICKSTORM Backdoor: UNC5221 PRC-Nexus APT Targeting VMware vSphere Infrastructure](https://intel.threadlinqs.com/threat/TL-2026-0313) — CRITICAL — 2026-04-02
- [APT41/Silver Dragon Expanding Enterprise Attack Surface — Google Drive C2, AppDomain Hijacking, Cloud/Supply Chain Targeting](https://intel.threadlinqs.com/threat/TL-2026-0292) — HIGH — 2026-03-27
- [Ivanti EPMM Unauthenticated RCE via Code Injection — CVE-2026-1281 & CVE-2026-1340 (Sleeper Shells)](https://intel.threadlinqs.com/threat/TL-2026-0223) — CRITICAL — 2026-03-13
- [Storm-2561 SEO Poisoning Campaign Distributing Fake Ivanti VPN Clients for Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-0218) — HIGH — 2026-03-12
- [Ivanti Endpoint Manager Pre-Auth Credential Leak via Authentication Bypass (CVE-2026-1603)](https://intel.threadlinqs.com/threat/TL-2026-0200) — CRITICAL — 2026-03-09
- [RESURGE Passive Rootkit — Ivanti Connect Secure CVE-2025-0282 Exploitation, CRC32 TLS Fingerprint C2, Covert SSH Channel, SPAWNCHIMERA/SPAWNSLOTH Variants, CISA MAR Update](https://intel.threadlinqs.com/threat/TL-2026-0163) — CRITICAL — 2026-03-02
- [Ivanti EPMM Dual-CVE Unauthenticated RCE Chain (CVE-2026-1281 + CVE-2026-1340) — CVSS 9.8, CISA KEV, Dutch Government Breached, Bulletproof Hosting IAB, Sleeper Webshells, 28K+ Attacking IPs](https://intel.threadlinqs.com/threat/TL-2026-0121) — CRITICAL — 2026-02-16
- [Ivanti EPMM Pre-Auth Remote Code Execution (CVE-2026-1281 / CVE-2026-1340)](https://intel.threadlinqs.com/threat/TL-2026-0002) — CRITICAL — 2026-01-29

## Threat actors targeting Ivanti

Named threat actors attributed to campaigns that involve Ivanti products or CVEs, with the number of linked campaigns:

- [UNC5221](https://intel.threadlinqs.com/actor/UNC5221) — 2 campaigns
- [APT35](https://intel.threadlinqs.com/actor/APT35) — 1 campaign
- [APT42](https://intel.threadlinqs.com/actor/APT42) — 1 campaign
- [DragonForce](https://intel.threadlinqs.com/actor/DragonForce) — 1 campaign
- [Salt Typhoon - G1045](https://intel.threadlinqs.com/actor/Salt%20Typhoon%20-%20G1045) — 1 campaign
- [Storm-1175](https://intel.threadlinqs.com/actor/Storm-1175) — 1 campaign
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 1 campaign
- [UTA0178](https://intel.threadlinqs.com/actor/UTA0178) — 1 campaign

## How to prioritise Ivanti patching

This order follows the data Threadlinqs holds for Ivanti, not a generic severity checklist:

- 19 of 22 Ivanti CVEs (86%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2019-11510](https://intel.threadlinqs.com/cve/CVE-2019-11510), [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520), [CVE-2019-11539](https://intel.threadlinqs.com/cve/CVE-2019-11539).
- 8 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2026-1602](https://intel.threadlinqs.com/cve/CVE-2026-1602) (0.1%), [CVE-2025-10573](https://intel.threadlinqs.com/cve/CVE-2025-10573) (0%).
- 10 CVEs score Critical and 10 High on CVSS v3 (maximum 10, average 8.5); sequence these after KEV and high-EPSS items.
- 7 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/ivanti
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
