Skip to content

Vendors

Ivanti

17records9productslast change2026-06-11RSSas of the 2026-09-07 snapshot

Rows per week, last 26 weeks

4 rows in the last 26 weeks, 0 in the week to 2026-09-070 this week

Rows, not records: one record that changed for four products is four rows and one record.

Choose a product · 9 products

Open the full product index. Counts beside products are records and are not added across products.

Every change, newest first

20 rows, shown as 14 lines
Every counted change to a CVE or CISA KEV record naming Ivanti, newest first. A line standing for the same change across several records or products says how many and opens to every one.
Changed on, The day the commit that carried this change was read. Where the same change spans several days, the first and the last, never a midpoint. Not dated means no commit could be located for the row.ChangeCVEProductWhat the record says now
2026-06-11Added to CISA KEVCVE-2026-10520Sentrylisted by CISA 2026-06-11federal fix due 2026-06-14
2026-05-07Added to CISA KEVCVE-2026-6973Endpoint Manager Mobile (EPMM)listed by CISA 2026-05-07federal fix due 2026-05-10
2026-04-08Added to CISA KEVCVE-2026-1340Endpoint Manager Mobile (EPMM)listed by CISA 2026-04-08federal fix due 2026-04-11
2026-03-09Added to CISA KEVCVE-2026-1603Endpoint Manager (EPM)listed by CISA 2026-03-09federal fix due 2026-03-23
2026-01-29Added to CISA KEVCVE-2026-12812 rows, one per record and productEndpoint Manager Mobile (EPMM)listed by CISA 2026-01-29federal fix due 2026-02-01
2026-01-29Added to CISA KEVCVE-2026-1281Endpoint Manager Mobile (EPMM)listed by CISA 2026-01-29federal fix due 2026-02-01
2026-01-29Added to CISA KEVCVE-2026-1281Endpoint Manager Mobile (EPMM)listed by CISA 2026-01-29federal fix due 2026-02-01
2025-10-08Ransomware use confirmedConnect Secure and Policy Securestated at publication Unknown, now states Known
2025-10-08Ransomware use confirmedCVE-2023-46805Connect Secure and Policy Securestated at publication Unknown, now states Known
2025-10-08Ransomware use confirmedCVE-2024-21887Connect Secure and Policy Securestated at publication Unknown, now states Known
2025-10-08Ransomware use confirmedCVE-2024-21893Connect Secure, Policy Secure, and Neuronsstated at publication Unknown, now states Known
2025-06-09Ransomware use confirmedCVE-2021-44529Endpoint Manager Cloud Service Appliance (EPM CSA)stated at publication Unknown, now states Known
2025-05-19Added to CISA KEVEndpoint Manager Mobile (EPMM)listed by CISA 2025-05-19federal fix due 2025-06-09
2025-05-19Added to CISA KEVCVE-2025-4427Endpoint Manager Mobile (EPMM)listed by CISA 2025-05-19federal fix due 2025-06-09
2025-05-19Added to CISA KEVCVE-2025-4428Endpoint Manager Mobile (EPMM)listed by CISA 2025-05-19federal fix due 2025-06-09
2025-05-12Ransomware use confirmedConnect Secure, Policy Secure, and ZTA Gatewaysstated at publication Unknown, now states Known
2025-05-12Ransomware use confirmedCVE-2025-0282Connect Secure, Policy Secure, and ZTA Gatewaysstated at publication Unknown, now states Known
2025-05-12Ransomware use confirmedCVE-2025-22457Connect Secure, Policy Secure, and ZTA Gatewaysstated at publication Unknown, now states Known
2025-04-07KEV required action changedCVE-2025-22457Connect Secure, Policy Secure and ZTA GatewaysCISA rewrote the required action
2025-04-04Added to CISA KEVCVE-2025-22457Connect Secure, Policy Secure and ZTA Gatewayslisted by CISA 2025-04-04federal fix due 2025-04-11
2025-03-10Added to CISA KEVEndpoint Manager (EPM)listed by CISA 2025-03-10federal fix due 2025-03-31
2025-03-10Added to CISA KEVCVE-2024-13159Endpoint Manager (EPM)listed by CISA 2025-03-10federal fix due 2025-03-31
2025-03-10Added to CISA KEVCVE-2024-13160Endpoint Manager (EPM)listed by CISA 2025-03-10federal fix due 2025-03-31
1 more row in this change is not listed here. Open all 3 rows
2023-11-03Product addedCVE-2023-32567Wavelinknot named as affected at publication, now names wavelink

A line that names a count is the same change on that many records or products, shown once; it opens to every member. A closed line is not reached by find-in-page; the flat view (Every row, flat →) is. Only counted changes are here: a change a kind's false-positive filter refused, such as a product line being renumbered, is in no figure on this page.

Data sources and quality

One vendor, every counted kind of change: the rows where a CVE record or a CISA KEV entry naming Ivanti changed after publication. The vendor name is the record's own text, compared without regard to case, so one organisation can appear under more than one spelling and this page holds the spellings that share its web address. Rows and records are different numbers and are never added together.

Not counted: a product line being renumbered, a boundary already named in the record's own description, and the other refusal classes are filtered as false positives and are in no figure here, so this page is what survived those filters rather than everything the catalog changed for this vendor.

Not checked: a record published before 2023 cannot have its state at publication recovered and was never compared, and a CISA KEV listing added before the first mirrored commit was never seen changing, so an absence from this page is not evidence that a record held.

How every one of these figures is measured, in full →

Shipped snapshot computed 2026-09-07 from catalog commit f5f9fc6fd7dc. Real findings, not live ones: records amended since are not reflected. A later fix version is evidence that the record changed, not evidence that the first fix was incomplete.