Is Ivanti the problem or a symptom of a systemic issue with network devices?CyberScoop·Apr 14, 13:57 UTC · Apr 14, 2025Exploit / PoC in the wild60
CISA orders federal agencies to disconnect Ivanti VPN instances by February 2Security Affairs·Feb 1, 19:46 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
Ivanti customers confront yet another actively exploited zeroCyberScoop·May 7, 21:50 UTC · May 7, 2026Exploit / PoC in the wildCVE-2026-6973CVE-2026-5787CVE-2026-5788+3 CVEs60
Critical Ivanti ZeroInfosecurity Magazine·Jan 9, 09:45 UTC · Jan 9, 2025Exploit / PoC in the wildCVE-2025-0282CVE-2025-028360
Ivanti’s EPMM is under active attack, thanks to two critical zeroCyberScoop·Feb 4, 15:22 UTC · Feb 4, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-1340CVE-2025-442860
Five Eyes alliance warns of attacks exploiting known Ivanti Gateway flawsSecurity Affairs·Mar 1, 14:01 UTC · Mar 1, 2024Exploit / PoCCVE-2023-46805CVE-2024-21887CVE-2024-21893+2 CVEs60
Two Ivanti ZeroInfosecurity Magazine·Jan 11, 09:30 UTC · Jan 11, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2023-35078+1 CVEs60
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14Security Affairs·Jun 14, 13:16 UTC · Jun 14, 2026Exploit / PoC in the wildCVE-2026-1052060
Fallout from latest Ivanti zeroCyberScoop·Feb 10, 00:03 UTC · Feb 10, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-134060
Ivanti enhances its solutions portfolio to drive secure, scalable, and streamlined IT operationsHelp Net Security·Oct 22, 00:00 UTC · Oct 22, 2025Exploit / PoC60
Ivanti Releases ZeroInfosecurity Magazine·Feb 1, 09:30 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21888+1 CVEs60
China-linked APT UNC5221 started exploiting Ivanti EPMM flaws shortly after their disclosureSecurity Affairs·May 26, 11:31 UTC · May 26, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-442860
Ivanti Connect Secure zero-day exploited by attackers (CVE-2025-0282)Help Net Security·Jan 8, 00:00 UTC · Jan 8, 2025Exploit / PoCCVE-2025-0282CVE-2025-028360
Ivanti fixed for 4 new issues in Connect Secure and Policy SecureSecurity Affairs·Apr 4, 08:10 UTC · Apr 4, 2024Exploit / PoCCVE-2024-21894CVE-2024-22052CVE-2024-22053+5 CVEs60
Ivanti integrity checker tool needs latest update to work, Five Eyes alert warnsCyberScoop·Feb 29, 21:37 UTC · Feb 29, 2024Exploit / PoC in the wild60
Ivanti Sentry zero-day vulnerability exploited, patch ASAP! (CVE-2023-38035)Help Net Security·Aug 24, 12:34 UTC · Aug 24, 2023Exploit / PoC in the wildCVE-2023-3803560
Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates ReleasedThe Hacker News·Apr 9, 04:57 UTC · Apr 9, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-134060
Ivanti provides temporary patches for actively exploited EPMM zero-day (CVE-2026-1281)Help Net Security·Feb 2, 10:44 UTC · Feb 2, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-134060
Ivanti EPMM vulnerabilities exploited in the wild (CVE-2025-4427, CVE-2025-4428)Help Net Security·May 16, 13:18 UTC · May 16, 2025Exploit / PoC in the wildCVE-2025-4427CVE-2025-4428CVE-2025-22462+1 CVEs60
Ivanti Neurons for App Control strengthens endpoint securityHelp Net Security·Oct 22, 00:00 UTC · Oct 22, 2024Exploit / PoC60
Chinese State Hackers Exploiting Newly Disclosed Ivanti FlawInfosecurity Magazine·Apr 4, 11:04 UTC · Apr 4, 2025Exploit / PoC in the wildCVE-2025-2245760
Three new Ivanti CSA zeroSecurity Affairs·Oct 8, 21:26 UTC · Oct 8, 2024Exploit / PoC in the wildCVE-2024-9379CVE-2024-9380CVE-2024-9381+2 CVEs60
Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively ExploitedThe Hacker News·Oct 11, 04:51 UTC · Oct 11, 2024Exploit / PoC in the wildCVE-2024-9379CVE-2024-9380CVE-2024-9381+3 CVEs60
Ivanti: Three CSA ZeroInfosecurity Magazine·Oct 9, 10:15 UTC · Oct 9, 2024Exploit / PoC in the wildCVE-2024-9379CVE-2024-9380CVE-2024-9381+2 CVEs60
Latest Ivanti Zero Day Exploited By Scores of IPsInfosecurity Magazine·Feb 6, 11:00 UTC · Feb 6, 2024Exploit / PoC in the wildCVE-2024-21893CVE-2023-46805CVE-2024-21887+2 CVEs60
CISA orders Ivanti devices targeted by Chinese hackers be disconnectedCyberScoop·Feb 1, 20:30 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2024-2188760
China-linked attacker hit France’s critical infrastructure via trio of Ivanti zeroCyberScoop·Jul 3, 16:02 UTC · Jul 3, 2025Exploit / PoC in the wildCVE-2024-8190CVE-2024-8963CVE-2024-938060
U.S. CISA adds Ivanti Connect Secure, Policy Secure and ZTA Gateways flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Apr 7, 19:39 UTC · Apr 7, 2025Exploit / PoC in the wildCVE-2025-22457160
China-linked group UNC5221 exploited Ivanti Connect Secure zero-day since midSecurity Affairs·Apr 3, 19:37 UTC · Apr 3, 2025Exploit / PoC in the wildCVE-2025-2245760
U.S. CISA adds Ivanti CSA and Fortinet bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 10, 11:11 UTC · Oct 10, 2024Exploit / PoC in the wildCVE-2024-23113CVE-2024-9379CVE-2024-9380+2 CVEs60
Ivanti Warns of Critical New ZeroInfosecurity Magazine·Aug 22, 10:00 UTC · Aug 22, 2023Exploit / PoCCVE-2023-38035CVE-2023-35078CVE-2023-35081+2 CVEs60
Ivanti: Customers ‘impacted’ by new zeroThe Record·Aug 21, 18:55 UTC · Aug 21, 2023Exploit / PoCCVE-2023-3803560
U.S. CISA adds a flaw in Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited Vulnerabilities catalogSecurity Affairs·May 7, 18:03 UTC · May 7, 2026Exploit / PoC in the wildCVE-2026-697360
U.S. CISA adds Ivanti Connect Secure, Policy Secure, and ZTA Gateways flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 9, 11:53 UTC · Jan 9, 2025Exploit / PoC in the wildCVE-2025-0282CVE-2025-028360
U.S. CISA adds new Ivanti Cloud Services Appliance Vulnerability to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 25, 07:42 UTC · Sep 25, 2024Exploit / PoC in the wildCVE-2024-8190CVE-2024-896360
Ivanti warns of a new actively exploited Cloud Services Appliance (CSA) flawSecurity Affairs·Sep 19, 20:49 UTC · Sep 19, 2024Exploit / PoC in the wildCVE-2024-8963CVE-2024-819060
U.S. CISA adds Ivanti Cloud Services Appliance Vulnerability to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 14, 15:45 UTC · Sep 14, 2024Exploit / PoC in the wildCVE-2024-819060
Ivanti Cloud Service Appliance flaw is being actively exploitedSecurity Affairs·Sep 14, 10:32 UTC · Sep 14, 2024Exploit / PoC in the wildCVE-2024-8190CVE-2024-2984760
Ivanti warns of a new auth bypass flaw in its Connect Secure, Policy Secure, and ZTA gateway devicesSecurity Affairs·Feb 9, 08:17 UTC · Feb 9, 2024Exploit / PoC in the wildCVE-2024-22024CVE-2023-46805CVE-2024-21887+2 CVEs60
Experts released PoC exploit for Ivanti Sentry CVE-2023Security Affairs·Aug 27, 15:03 UTC · Aug 27, 2023Exploit / PoC in the wildCVE-2023-3803560