← Vulnerability feed

Vulnerability record · CVE-2021-44529 · published 8 December 2021

CVE-2021-44529: Ivanti EPM Cloud Services Appliance unauthenticated code injection

Ivanti · Endpoint Manager Cloud Services Appliance

Ivanti Endpoint Manager Cloud Services Appliance (CSA) contains a code injection flaw (CWE-94) that lets an unauthenticated remote user execute arbitrary code. It carries a critical CVSS 3.1 score of 9.8 and is listed in CISA's KEV catalog, so it is a high-value target for defenders.

9.8 CVSS 3.1 Critical CISA KEV since 25 Mar 2024 Known ransomware use EPSS 99% · top 0.1% CWE-94 · Code injection
9.8CVSS 3.1 base score, v2 7.5
99%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 4 tagged exploit
4 Aug 2026Last modified by NVD

Description

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated remote code execution, KEV listing with known ransomware use, and near-maximum EPSS make this an urgent patch.

What it is

Ivanti Endpoint Manager Cloud Services Appliance (CSA) contains a code injection flaw (CWE-94) that lets an unauthenticated remote user execute arbitrary code. It carries a critical CVSS 3.1 score of 9.8 and is listed in CISA's KEV catalog, so it is a high-value target for defenders.

Impact

An attacker gains remote code execution on the CSA, though the description states execution occurs with limited permissions as the 'nobody' user. That still allows code execution on an internet-facing appliance, which can be a foothold for further compromise.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw is in the CSA itself, so any exposed instance is directly at risk.

Exploitation

CISA added it to KEV on 2024-03-25 with a 2024-04-15 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99105 (99.9th percentile). Public exploit references exist on Packet Storm, indicating active exploitation.

What to do

  • Apply the vendor patch or mitigation from Ivanti advisory SA-2021-12-02 immediately.
  • If no patch can be applied, discontinue use of the CSA or isolate it from untrusted networks per CISA guidance.
  • Restrict network access to the CSA management interface to trusted hosts only.
  • Monitor for and investigate any signs of compromise on CSA hosts, given known ransomware use.
  • Verify the CSA is not directly internet-exposed and remove unnecessary exposure.

Detection

  • Hunt for unexpected processes or command execution on CSA hosts, especially running as the 'nobody' user.
  • Review CSA and web server logs for anomalous requests or injection patterns targeting the appliance.
  • Monitor network egress from CSA hosts for command-and-control or lateral movement activity.
  • Alert on any new or unusual files, scripts, or scheduled tasks created on the CSA.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-44529 to the Known Exploited Vulnerabilities catalog on 25 March 2024 as "Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability ". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 15 April 2024.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-44529 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2024-8963Ivanti CSA path traversal allows unauthenticated access to restricted functionsIvanti Cloud Services Appliance (CSA) before 4.6 Patch 519 contains a path traversal flaw (CWE-22) that lets a remote, unauthenticated attacker reach…KEVEPSS 99%analysed7.2CVE-2024-9379Ivanti CSA admin console SQL injectionIvanti Cloud Services Appliance (CSA) before version 5.0.2 contains a SQL injection flaw in its admin web console (CWE-89). A remote attacker who alr…KEVEPSS 44%analysed7.2CVE-2024-9380Ivanti CSA admin console OS command injection enables RCEIvanti Cloud Services Appliance (CSA) before version 5.0.2 contains an OS command injection flaw in its admin web console. An attacker who already ho…KEVEPSS 60%analysed7.2CVE-2024-9381Ivanti endpoint manager cloud services appliance path traversal vulnerabilityPath traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.EPSS 16%8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed

Source: NIST National Vulnerability Database (record CVE-2021-44529), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.