Ivanti
Ivanti Endpoint Manager: vulnerabilidades y CVE
Ivanti Endpoint Manager tiene 119 vulnerabilidades publicadas, 26 de ellas en los últimos 12 meses. 10 son críticas y 5 figuran en el catálogo de explotación activa de CISA.
CVE119
Últimos 12 meses26
Críticas10
Explotadas activamente5
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-1603 | Alta (7.5) | 88% | ⚠ Explotación activa | 10 feb 2026 | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data. |
| CVE-2024-13160 | Alta (7.5) | 91% | ⚠ Explotación activa | 14 ene 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. |
| CVE-2024-13159 | Alta (7.5) | 100% | ⚠ Explotación activa | 14 ene 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. |
| CVE-2024-13161 | Alta (7.5) | 90% | ⚠ Explotación activa | 14 ene 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information. |
| CVE-2024-29824 | Alta (8.8) | 100% | ⚠ Explotación activa | 31 may 2024 | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-18129 | Alta (8.1) | 1.5% | — | 11 ago 2026 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections. |
| CVE-2026-18127 | Alta (7.7) | 0.72% | — | 11 ago 2026 | External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage. |
| CVE-2026-18125 | Alta (7.5) | 1.6% | — | 11 ago 2026 | An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service. |
| CVE-2026-8111 | Alta (8.8) | 1.6% | — | 12 may 2026 | SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution. |
| CVE-2026-8110 | Alta (7.8) | 0.37% | — | 12 may 2026 | Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges. |
| CVE-2026-8109 | Media (6.5) | 1.1% | — | 12 may 2026 | An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials. |
| CVE-2026-1603 | Alta (7.5) | 88% | ⚠ Explotación activa | 10 feb 2026 | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data. |
| CVE-2026-1602 | Media (6.5) | 0.73% | — | 10 feb 2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-13662 | Alta (7.8) | 0.58% | — | 9 dic 2025 | Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User… |
| CVE-2025-13661 | Alta (8) | 1.4% | — | 9 dic 2025 | Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required. |
| CVE-2025-13659 | Alta (8.8) | 2.0% | — | 9 dic 2025 | Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to… |
| CVE-2025-10573 | Media (6.1) | 33% | — | 9 dic 2025 | Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required. |
| CVE-2025-10918 | Alta (7.1) | 0.24% | — | 11 nov 2025 | Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk |
| CVE-2025-62392 | Media (6.5) | 0.82% | — | 13 oct 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-62391 | Media (6.5) | 0.82% | — | 13 oct 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-62390 | Media (6.5) | 1.7% | — | 13 oct 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-62389 | Media (6.5) | 1.7% | — | 13 oct 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-62388 | Media (6.5) | 0.82% | — | 13 oct 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-62387 | Media (6.5) | 1.7% | — | 13 oct 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-62386 | Media (6.5) | 0.82% | — | 13 oct 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-62385 | Media (6.5) | 0.82% | — | 13 oct 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-62384 | Media (6.5) | 0.83% | — | 13 oct 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-62383 | Media (6.5) | 0.83% | — | 13 oct 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-11623 | Media (6.5) | 0.83% | — | 13 oct 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. |
| CVE-2025-9713 | Alta (8.8) | 15% | — | 13 oct 2025 | Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. |
| CVE-2025-11622 | Alta (7.8) | 0.78% | — | 13 oct 2025 | Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges. |
| CVE-2025-9872 | Alta (8.8) | 14% | — | 9 sept 2025 | Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. |
| CVE-2025-9712 | Alta (8.8) | 21% | — | 9 sept 2025 | Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required. |
| CVE-2025-7037 | Alta (7.2) | 1.1% | — | 8 jul 2025 | SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database |
| CVE-2025-6996 | Alta (8.4) | 0.22% | — | 8 jul 2025 | Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.