Skip to content
Active Exploitation of Vulnerabilities in Ivanti and SolarWinds Products

Active Exploitation of Vulnerabilities in Ivanti and SolarWinds Products

First seen 10 Mar 2026, 08:09 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 13, 2026 at 17:39 UTC

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of vulnerabilities in Ivanti Endpoint Manager, SolarWinds Web Help Desk, and VMware Workspace ONE. The vulnerabilities include CVE-2025-26399, CVE-2026-1603, and CVE-2021-22054, all of which have been added to CISA's Known Exploited Vulnerabilities (KEV) list as of March 9, 2026.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 209d ago How this analysis works

Timeline

2021-12-17
CVE-2021-22054 published
2025-09-23
CVE-2025-26399 published and first public PoC released
2026-02-10
CVE-2026-1603 published
2026-03-09
CVE-2025-26399, CVE-2026-1603, CVE-2021-22054 added to CISA KEV

More articles in this cluster (12)

Following this threat?

Track Ivanti and CVE-2021-22054 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed