boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Tuesday, October 6, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Ivanti

Vendor reference — Ivanti · sector: Network & Infrastructure. Cumulative disclosure record across the archive.

Follow Ivanti — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs4424
KEV entries255
Rate & severity
KEV/100Med CVSSMed EPSSCHML
56.88.8.6161182330

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▂▃▁▁▁▁▃▁▁▁▂▁▁▂▂▂▁▁▄▁▁▂▂▁▁▁▁▁▁▁▂▂▁▁▂▄▂▃█▁

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-110
2025-120
2026-012
2026-021
2026-030
2026-040
2026-052
2026-064
2026-072
2026-083
2026-0910
2026-100

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2023-3508210.0100.0CRITICALYES2023-08-15
CVE-2023-350789.8100.0CRITICALYES2023-07-25
CVE-2024-75939.8100.0CRITICALYES2024-08-13
CVE-2024-218879.1100.0CRITICALYES2024-01-10
CVE-2024-218938.2100.0HIGHYES2024-01-31
CVE-2024-131599.8100.0CRITICALYES2025-01-14
CVE-2023-468058.2100.0HIGHYES2024-01-10
CVE-2025-224579.8100.0CRITICALYES2025-04-04
CVE-2025-02829.0100.0CRITICALYES2025-01-08
CVE-2023-380359.8100.0CRITICALYES2023-08-21
CVE-2024-298249.6100.0CRITICALYES2024-05-31
CVE-2025-44275.3100.0MEDIUMYES2025-05-13
CVE-2026-1052010.0100.0CRITICALYES2026-06-11
CVE-2026-12819.899.9CRITICALYES2026-01-29
CVE-2026-13409.899.9CRITICALYES2026-01-29

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-835278.177.8HIGH—2026-09-08
CVE-2026-188518.862.3HIGH—2026-09-08
CVE-2026-127459.881.7CRITICAL—2026-09-08
CVE-2026-127449.882.4CRITICAL—2026-09-08
CVE-2026-126518.873.2HIGH—2026-09-08
CVE-2026-126508.874.3HIGH—2026-09-08
CVE-2026-126488.873.2HIGH—2026-09-08
CVE-2026-126478.868.1HIGH—2026-09-08
CVE-2026-126468.868.1HIGH—2026-09-08
CVE-2026-126458.869.0HIGH—2026-09-08
CVE-2026-181298.172.6HIGH—2026-08-11
CVE-2026-181277.752.4HIGH—2026-08-11
CVE-2026-181257.574.9HIGH—2026-08-11
CVE-2026-149036.566.7MEDIUM—2026-07-14
CVE-2026-149026.151.7MEDIUM—2026-07-14

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-105202026-06-1110.0100.0CRITICAL
CVE-2026-69732026-05-077.284.4HIGH
CVE-2026-13402026-04-089.899.9CRITICAL
CVE-2026-16032026-03-098.699.8HIGH
CVE-2026-12812026-01-299.899.9CRITICAL
CVE-2025-44272025-05-195.3100.0MEDIUM
CVE-2025-44282025-05-197.299.7HIGH
CVE-2025-224572025-04-049.8100.0CRITICAL
CVE-2024-131592025-03-109.8100.0CRITICAL
CVE-2024-131602025-03-109.899.8CRITICAL
CVE-2024-131612025-03-109.899.8CRITICAL
CVE-2025-02822025-01-089.0100.0CRITICAL
CVE-2024-93792024-10-097.298.7HIGH
CVE-2024-93802024-10-097.299.1HIGH
CVE-2024-298242024-10-029.6100.0CRITICAL
CVE-2024-75932024-09-249.8100.0CRITICAL
CVE-2024-89632024-09-199.499.9CRITICAL
CVE-2024-81902024-09-137.299.8HIGH
CVE-2024-218932024-01-318.2100.0HIGH
CVE-2023-350822024-01-1810.0100.0CRITICAL
CVE-2023-468052024-01-108.2100.0HIGH
CVE-2024-218872024-01-109.1100.0CRITICAL
CVE-2023-380352023-08-229.8100.0CRITICAL
CVE-2023-350812023-07-317.299.2HIGH
CVE-2023-350782023-07-259.8100.0CRITICAL

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2023-350782023-08-151148
CVE-2023-350812023-08-211142
CVE-2023-380352023-09-121120
CVE-2024-218872024-01-22988
CVE-2023-468052024-01-22988
CVE-2024-218932024-02-02977
CVE-2023-350822024-02-08971
CVE-2024-81902024-10-04732
CVE-2024-89632024-10-10726
CVE-2024-75932024-10-15721

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.