Hubbry Logo
search
logo
Ivanti
Ivanti
current hub
1812300

Ivanti

logo
Community Hub0 Subscribers
Read side by side
from Wikipedia

Ivanti (/ˌˈvɒnt/) is an IT software company headquartered in South Jordan, Utah, United States. It produces software for IT Security, IT Service Management (ITSM), IT Asset Management (ITAM), Unified Endpoint Management (UEM), Identity Management, Patch Management and supply chain management. It was formed in January 2017 with the merger of LANDESK and HEAT Software, and later acquired Cherwell Software. The company became more widely known after security incidents related to the VPN hardware it sells.

Key Information

History

[edit]

LANDESK

[edit]

LAN Systems was founded in 1985 and its software products acquired by Intel in 1991 to form its LANDESK division. LANDESK introduced the desktop management category in 1993. In 2002 LANDESK Software became a standalone company with headquarters near Salt Lake City, Utah. In 2006, Avocent purchased the company for $416 million. Also in 2006, LANDESK added process management technologies to its product line and extended into the consolidated service desk market with LANDESK Service Desk. In 2010 LANDESK was acquired by private equity firm Thoma Bravo.

LANDESK bought supply chain software company Wavelink in 2012, network vulnerability assessment and patch management company Shavlik in 2013, application software company Naurtech Corporation in 2014, data visualisation company Xtraction Solutions in 2015.[1] and AppSense, a provider of secure user environment management technology, in 2016.

Lumension Security

[edit]

Lumension Security, Inc was founded as High Tech Software in 1991 and headquartered in Scottsdale, Arizona[2] The company was rebranded as PatchLink Corporation in 1999. In 2006, Patrick Clawson was appointed chairman, CEO and president[3] The company then adopted the Lumension name in 2007.[4]

In 2009 Lumension acquired Securityworks,[5] and in 2012 acquired CoreTrace.[6]

Lumension products traditionally competed in the endpoint management and security industry against Sophos, McAfee, Kaspersky Lab, Symantec and Trend Micro among others.

HEAT

[edit]

HEAT software was a producer of software for IT Service Management and Endpoint Management formed in 2015 by the merger of FrontRange Solutions and Lumension Security.

Ivanti

[edit]

In January 2017 Clearlake Capital, owner of HEAT Software, purchased LANDESK from Thoma Bravo.[7] On January 23, 2017, LANDESK and HEAT Software merged to form Ivanti.[8][9] The combined company has 1,800 employees in 23 countries[10][11] and markets some products with references to their original names such as Wavelink supply chain software[12] and Ivanti patch product ‘powered by Shavlik’.

On April 12, 2017, Ivanti acquired Concorde Solutions, a UK based Software Asset Management company.[13] In July 2017, Ivanti acquired RES Software, a US and Netherlands based company producing automation and identity management software.[14] Later merged in 2018 into the Workspace Manager product.[15]

In September 2020, Ivanti entered into an agreement to acquire US based Unified Endpoint Management company MobileIron for $872 million[16] and San Jose, California based Pulse Secure, for undisclosed terms.[17] On December 1, 2020, Ivanti announced those acquisitions completed.[18]

On January 26, 2021, Ivanti announced the intent to acquire Cherwell Software.[19]

On August 2, 2021, Ivanti acquired RiskSense, a pioneer in risk-based vulnerability management and prioritization, to drive the next evolution of patch management.[20]

Controversies

[edit]

2021 Pulse Connect Secure hack

[edit]

On April 20, 2021, cybersecurity firm FireEye reported that hackers with suspected Chinese government ties exploited Pulse Secure VPN to break into government agencies, defense companies and financial institutions in Europe and the US. The report detailed how hackers repeatedly took advantage of several known and one novel flaw in Pulse Secure VPN to gain access to dozens of organizations in the defense industrial sector.[21][22] The US Department of Homeland Security confirmed the intrusions in a public advisory, urging network administrators to scan for signs of compromise. Ivanti published an emergency workaround which DHS urged network admins to install.[23] The Cybersecurity and Infrastructure Security Agency ordered federal civilian agencies to take several steps to reduce risk from the suspected breach.[24] FireEye reported that some of the intrusions using the vulnerabilities began as early as August 2020, conducted by those with suspected ties to the Chinese government. There were similarities between the hack and intrusions in 2014 and 2015 conducted by a Chinese espionage actor named APT5.[22] After further examination, CISA discovered that at least 5 federal agencies had been breached, among 24 agencies that use the Pulse Connect Secure products.[25]

Other incidents

[edit]

In January 2024, Chinese government hackers were reported to have targeted Ivanti software to break into other organizations.[26]

References

[edit]
[edit]
Revisions and contributorsEdit on WikipediaRead on Wikipedia
from Grokipedia
Ivanti, Inc. is a multinational IT software company headquartered in South Jordan, Utah, that develops and provides solutions for managing and securing IT assets, endpoints, and operations across hybrid work environments.[1][2] Formed in 2017 through the merger of LANDESK and HEAT Software, it combines over 30 years of experience in enterprise IT management to automate workflows, enforce zero trust security, and deliver IT service management tools.[2][3] Ivanti's platform, including products like Neurons for AI-driven operations and offerings in unified endpoint management, supports discovery, patching, and remediation of devices from cloud to edge, serving more than 34,000 customers with approximately 3,100 employees across 18 offices in 23 countries.[2][4] The company has pursued aggressive growth via acquisitions, such as RES Software in 2017 for workspace automation, MobileIron and Pulse Secure in 2020 to bolster mobile and network security, Cherwell Software in 2021 for enhanced service management, and RiskSense in 2021 to advance risk-based vulnerability prioritization.[5][6][7][8] Despite these expansions, Ivanti has encountered significant challenges with product security, particularly in its Connect Secure and Policy Secure gateways, where multiple zero-day vulnerabilities since 2021 have enabled widespread exploitation by advanced persistent threats, including state-sponsored actors, prompting mandatory mitigations from CISA and scrutiny over delayed patching and response processes.[9][10][11] In response, Ivanti has committed to reengineering its software development lifecycle to prioritize security hardening, though ongoing disclosures of unpatched flaws in Endpoint Manager underscore persistent risks in its ecosystem.[12][13]

Company Overview

Founding and Corporate Evolution

Ivanti traces its origins to 1985, when LANSystems was established as a pioneer in IT systems management.[14] LANSystems was acquired by Intel in 1991 and operated as the LANDESK division until its spin-off as an independent company in 2002.[14] Concurrently, HEAT Software developed IT service management solutions, positioning itself as a SaaS-based provider.[15] In January 2017, private equity firm Clearlake Capital acquired LANDESK from Thoma Bravo and merged it with its portfolio company HEAT Software to create a unified entity.[16] The merger combined LANDESK's endpoint management expertise with HEAT's service management capabilities, integrating prior acquisitions such as AppSense, Shavlik, and Wavelink under a single platform.[17] On January 23, 2017, the combined organization adopted the name Ivanti, marking its formal founding as a distinct corporate entity focused on IT operations and security.[18] The corporate evolution immediately following the merger emphasized rebranding and product unification to streamline offerings across IT asset management, service desk, and security functions.[19] This transition involved consolidating multiple legacy brands into Ivanti, a process described by company leadership as a multi-month effort to align technology stacks and market positioning.[20] By mid-2017, Ivanti positioned itself as an innovation leader, leveraging over 30 years of combined experience from its predecessors to address enterprise IT challenges.[2]

Headquarters and Leadership

Ivanti maintains its corporate headquarters at 10377 South Jordan Gateway, Suite 400, South Jordan, Utah 84095, United States.[1] Established as the global hub following groundwork in 2018 for the facility's completion by early 2019, the location supports core operations in IT management and security software development.[21] The company operates 18 offices across 23 nations, with significant presence in regions including Europe, Asia-Pacific, and Latin America, accommodating approximately half of its workforce outside the United States.[2] Dennis Kozak has served as Chief Executive Officer since January 1, 2025, following his promotion from Chief Operating Officer, a role he held since April 2022.[22] Prior to Ivanti, Kozak accumulated over 20 years in sales leadership and business transformation at Avaya and CA Technologies, succeeding Jeff Abbott in steering strategic direction and growth amid the company's focus on cybersecurity and IT solutions.[23] The executive leadership team comprises experienced professionals in finance, legal, marketing, revenue, and development, emphasizing operational efficiency and customer-centric innovation. Key members include Peter de Bock as Chief Financial Officer, overseeing finance and facilities with more than 30 years in software finance from firms like Inovalon and CA Technologies; Brooke Johnson as Chief Legal Counsel and SVP of HR and Security, managing compliance and human resources since 2017; Melissa Puls as Chief Marketing Officer and SVP of Customer Success and Renewals; Michael Mills as Chief Revenue Officer, directing global sales with over 25 years of experience; and Radu Patrichi as SVP and Chief Corporate Development Officer, handling mergers and acquisitions with a background at VMware and Autodesk.[22] This structure supports Ivanti's emphasis on scalable IT service management and endpoint security.[22]

Core Business Model

Ivanti's core business model centers on developing and licensing enterprise software solutions that integrate IT service management, endpoint security, and asset management to automate operations, mitigate risks, and enhance productivity across hybrid environments. The company targets business customers, including large organizations with distributed workforces, by offering platforms that provide visibility into IT assets from cloud to edge devices. This approach emphasizes unification of disparate tools into a single interface, reducing manual interventions and enabling proactive issue resolution.[2][24] Revenue generation relies predominantly on software licensing and subscription fees, with models tailored to deployment types such as on-premises installations or cloud-based SaaS via the Ivanti Neurons platform. Under device-based licensing, organizations purchase licenses for each registered physical or virtual device on which the software operates, while enterprise license agreements permit usage across multiple users and devices under broader terms. Subscription licenses incorporate maintenance, updates, and upgrades, contrasting with potential perpetual licenses for legacy on-premises products. Professional services, including implementation, customization, and training, along with annual support contracts, supplement licensing income.[25][26][27] Distribution occurs through a hybrid model combining direct sales to key accounts with a partner ecosystem of over 7,000 resellers, integrators, and managed service providers, who earn commissions on sales and support deliveries. This structure supports global scalability, serving approximately 34,000 customers while leveraging partners for localized implementation and expansion into non-IT service management areas. Ivanti's emphasis on recurring revenue from subscriptions aligns with industry shifts toward cloud adoption, though dependency on robust security delivery influences customer retention amid potential churn risks.[2][28][29]

History

Predecessor Companies

Ivanti traces its origins to the merger of two primary predecessor companies, LANDESK and HEAT Software, completed on January 23, 2017, under the backing of Clearlake Capital Group, which acquired LANDESK from Thoma Bravo to facilitate the combination.[17][18] This union integrated LANDESK's endpoint management expertise with HEAT Software's IT service management capabilities, forming a unified platform for IT operations and security solutions.[3] LANDESK evolved from LANSystems, established in 1985 to develop network management tools, which Intel acquired in 1991 and reorganized as its LANDESK division focused on systems management software.[14] The division operated within Intel until its spin-off as an independent entity in September 2002, subsequently growing through private equity ownership before the 2017 merger.[14] By the time of the merger, LANDESK served over 20,000 organizations with solutions for endpoint visibility, patching, and asset management.[14] HEAT Software emerged in February 2015 from the merger of FrontRange Solutions, founded in 1989 in Colorado Springs and known for its HEAT suite of IT service desk and helpdesk software, and Lumension Security, established in 1991 in Scottsdale, Arizona, specializing in endpoint protection, patch management, and vulnerability assessment.[30] Both FrontRange and Lumension had undergone prior acquisitions and rebrandings—FrontRange from earlier iterations of customer service tools, and Lumension from its roots in security software—but the 2015 combination, also driven by Clearlake Capital, created a broader service and endpoint management portfolio that complemented LANDESK's offerings in the Ivanti formation.[30]

Formation and Early Mergers (2017)

Ivanti was formed on January 23, 2017, through the merger of LANDESK Software, a provider of IT systems management solutions, and HEAT Software, a SaaS-based IT service management firm, both under the backing of private equity firm Clearlake Capital Group.[17] The combination aimed to create a unified platform for IT operations, security, and service management by integrating LANDESK's endpoint management strengths with HEAT's service desk capabilities.[31] Clearlake Capital facilitated the merger by acquiring LANDESK from previous owner Thoma Bravo earlier that month and pairing it with its existing portfolio company HEAT Software, with the transaction closing in January 2017.[16] Following the formation, Ivanti pursued early expansions to bolster its software asset management offerings. On April 12, 2017, it acquired Concorde Solutions, a UK-based provider of SaaS-based software optimization and IT asset management tools, enhancing capabilities in license compliance and cost optimization for enterprise clients.[32] This acquisition marked Ivanti's ninth in five years across its predecessor entities, focusing on integrating Concorde's expertise in software license analytics.[33] In July 2017, Ivanti further expanded its portfolio by acquiring RES Software, a Dutch firm specializing in workspace automation, identity provisioning, and user environment management.[34] The deal, announced on July 5, strengthened Ivanti's user-centric IT solutions, particularly in automating desktop and application delivery for secure, efficient workspaces.[35] These initial post-formation moves positioned Ivanti as a more comprehensive IT operations provider amid growing demand for integrated security and automation tools.[3]

Major Acquisitions (2018-2021)

In September 2020, Ivanti announced agreements to acquire MobileIron, a provider of mobile-centric unified endpoint management solutions, for approximately $872 million in cash, and Pulse Secure, a company specializing in secure access service edge and zero trust network access technologies.[36][6] The acquisitions, completed on December 1, 2020, aimed to enhance Ivanti's capabilities in endpoint security and automation for distributed workforces, integrating MobileIron's device management with Pulse Secure's access controls to address rising remote work demands amid the COVID-19 pandemic.[37] These moves expanded Ivanti's portfolio to cover over 40,000 endpoints across hybrid environments, combining the targets' technologies for unified visibility and threat response.[38] On January 26, 2021, Ivanti announced its intent to acquire Cherwell Software, a developer of IT service management platforms focused on service desk automation and workflow orchestration. The deal, completed later that year for an undisclosed amount, integrated Cherwell's no-code tools with Ivanti's existing asset and service management offerings, enabling customers to consolidate IT operations and reduce silos in service delivery.[39] This acquisition targeted improvements in employee experience and operational efficiency, particularly for service request handling and change management in large enterprises. In August 2021, Ivanti acquired RiskSense, a Sunnyvale-based firm specializing in risk-based vulnerability management and prioritization, for an undisclosed sum.[8] The integration of RiskSense's platform allowed Ivanti to advance its patch management by incorporating predictive risk scoring and automated remediation, helping organizations prioritize vulnerabilities based on exploit likelihood and business impact rather than sheer volume.[40] This bolstered Ivanti's security posture amid escalating ransomware threats, providing tools for proactive threat hunting and compliance in dynamic IT environments.[8]

Expansion and Recent Milestones (2022-2025)

In 2022, Ivanti launched its Global Partner Portal and Campaign Central, providing partners with a personalized, role-based platform to generate leads, access training, and manage campaigns, aimed at enhancing partner enablement and business growth.[41] By May 2024, the company introduced the Ivanti One Tech Alliance Marketplace, a program connecting customers with partner solutions for integrations in IT service management, endpoint security, and automation, fostering ecosystem expansion without direct acquisitions.[42] On January 9, 2025, Ivanti appointed Dennis Kozak as CEO, succeeding Jeff Abbott; Kozak had previously overseen sales, marketing, and operations during a phase of product integration from prior acquisitions, positioning the company for continued operational scaling.[43] In March 2025, Ivanti partnered with Project Hosts to accelerate FedRAMP High authorization for its cloud services, enabling faster deployment of secure IT solutions for U.S. government agencies and supporting federal market expansion.[44] A key financial milestone occurred on May 7, 2025, when Ivanti completed a refinancing transaction infusing $350 million in new capital and extending debt maturities, providing resources for strategic initiatives in product development and security enhancements amid competitive pressures in enterprise IT.[45][46] Throughout 2025, Ivanti rolled out quarterly product releases emphasizing efficiency and risk reduction, including Q1 updates for productivity tools, Q2 features like ring deployment for patch management and Android 16 certification in endpoint management, and Q3 improvements for IT and security team workflows.[47] Product milestones included the July 24, 2025, release of Ivanti Connect Secure 22.8, advancing a "Secure by Design" approach with enhanced vulnerability mitigations and policy controls, and October enhancements across endpoint, security, and service management solutions for scalable IT environments and Windows 11 support.[48][49][50] Ivanti's innovations garnered multiple 2025 awards, such as the Stratus Award for Cloud Innovation and Cloud Computing Product of the Year for Ivanti Neurons for Patch Management, recognizing its cloud-native architecture for rapid deployment and security excellence, alongside Cybersecurity Excellence Awards in patch management categories.[51][52][53]

Products and Services

Endpoint Management Solutions

Ivanti Endpoint Manager serves as the company's flagship unified endpoint management (UEM) platform, enabling IT teams to discover, inventory, configure, patch, and secure endpoints across Windows, macOS, Linux, Chrome OS, and IoT devices from a single console.[54] This solution integrates asset management, software deployment, and remote control capabilities to automate routine tasks and reduce manual intervention.[55] Core features include automated patch management to address vulnerabilities promptly, software distribution for efficient application deployment, and OS imaging for standardized device provisioning.[54] Endpoint security components provide layered defenses against zero-day threats, firewall intrusions, and unauthorized processes through device lockdown, behavioral monitoring, and location-aware policies.[56] The platform supports remote troubleshooting via integrated remote control tools, allowing administrators to resolve issues without physical access.[54] Ivanti Neurons for UEM extends these functionalities with AI-driven, continuous endpoint discovery and inventory, offering real-time visibility into managed devices including mobile platforms like iOS, Android, and Windows.[57] This SaaS-based extension facilitates policy enforcement for both corporate and BYOD scenarios, integrating threat detection to mitigate risks from mobile threats.[58] Secure UEM packages, such as Professional and Premium editions, provide tiered options for vulnerability management and compliance reporting, emphasizing proactive endpoint hardening.[59] The solution's architecture supports hybrid environments, combining on-premises deployment with cloud scalability to handle diverse device fleets, as evidenced by its compatibility with over 1,000 third-party integrations for extended functionality.[54] Recent updates, including the 2024.4 release, have enhanced automation for patching and deployment workflows to improve operational efficiency.[60] Ivanti also offers specialized remote device management through its cloud-based Ivanti Neurons for MDM, which manages and secures iOS, iPadOS, Android, macOS, ChromeOS, and Windows devices. Key features include simple over-the-air onboarding and provisioning using services like Apple Business Manager, Google Zero-Touch Enrollment, and Windows Autopilot for automated device enrollment with apps, settings, and security configurations. Support tools enhance remote capabilities: Help@Work allows IT to remotely view and control a user's iOS or Android device screen (with consent) to troubleshoot issues efficiently over any network, reducing downtime and costs. Ivanti Tunnel provides a versatile multi-OS VPN solution that authorizes specific mobile apps to access corporate resources behind the firewall without user interaction, securing traffic while preserving privacy. Ivanti emphasizes using remote control (integrated in Endpoint Manager for Windows/macOS and Help@Work for mobile) primarily for real-time troubleshooting of issues, rather than routine device management tasks like updates or configurations, which should leverage MDM automation for scalability and efficiency.

Security and Exposure Management

Ivanti's exposure management offerings center on a solution that integrates attack surface management, risk-based vulnerability management, and automated remediation to identify and mitigate digital risks across hybrid environments including IT, cloud, IoT, and OT assets.[61] This approach emphasizes proactive identification of exposures such as software vulnerabilities, misconfigurations, and weak credentials through active and passive scanning methods alongside agentless monitoring, providing visibility into servers, endpoints, mobile devices, websites, and internet-facing assets.[61][62] Unlike traditional vulnerability scanning, which focuses narrowly on known flaws, exposure management adopts a holistic view by correlating asset data with exploitability and business impact to prioritize threats.[62] Risk assessment employs proprietary metrics including the Vulnerability Risk Rating (VRR) and Ivanti RS³ scores, which leverage AI-driven analysis to evaluate real-world severity beyond standard CVSS ratings, factoring in elements like active exploitation trends and organizational context.[61] Validation of prioritized exposures occurs via integrated tools for breach and attack simulation (BAS), continuous automated red teaming (CART), and penetration testing as a service (PTaaS), ensuring remediation targets verifiable threats.[61] The solution integrates with the Ivanti Neurons platform for seamless workflow automation, enabling IT teams to deploy patches, configure fixes, or isolate assets through bots and orchestration without manual intervention.[61] Complementing these capabilities, Ivanti Security Controls provides endpoint-focused security features such as automated patch deployment for detected vulnerabilities across Windows, Red Hat Linux, and CentOS systems, including agentless options to minimize disruption.[63] It supports dynamic application allowlisting, granular privilege management via just-enough administration (JIT), and real-time dashboards for compliance monitoring, directly linking CVE identifications to patch lists for rapid response.[63] These tools collectively aim to reduce mean time to remediation by aligning security operations with empirical risk data, though effectiveness depends on accurate asset inventory and timely integration.[64] As of 2025 updates, enhancements include expanded external attack surface management (EASM) for continuous monitoring of internet-exposed assets.[61]

IT Service and Asset Management

Ivanti offers IT service management (ITSM) capabilities primarily through Ivanti Neurons for ITSM, a platform designed to automate workflows and enhance help desk operations across incident, problem, and change management processes.[65] This solution supports ITIL-compliant practices by enabling no-code, drag-and-drop workflow design, AI-powered chatbots for self-service resolution, and proactive issue detection to shift support from reactive to preventive.[65] It provides role-based dashboards for real-time insights, multi-channel ticket management, and mobile accessibility, available in cloud, on-premises, or hybrid deployments to suit varying organizational scales.[65] Automation reduces manual tasks, accelerating resolutions while integrating with existing phone systems for intelligent routing and post-incident feedback via bots.[65] For IT asset management (ITAM), Ivanti delivers Ivanti Neurons for ITAM, which consolidates hardware, software, virtual, and cloud asset data for full lifecycle tracking from procurement to disposal.[66] Key features include real-time automated discovery and normalization of assets, warranty and location monitoring, and compliance enforcement to mitigate risks and curb overspend through accurate inventory reconciliation.[66] The platform, hosted on an ISO 27001-certified cloud, integrates with discovery tools to map asset linkages and supports software license optimization, providing at-a-glance visibility into usage and threats.[66] Ivanti emphasizes seamless integration between its ITSM and ITAM solutions, feeding asset data into the configuration management database (CMDB) to automate service requests, incident triage, and compliance workflows.[67] This alignment enables shared visibility, such as linking asset status to service tickets, reducing redundancies and enhancing operational efficiency across IT environments.[67] For instance, ITAM insights inform ITSM processes like change approvals by verifying asset configurations, while ITSM escalations trigger ITAM updates for proactive maintenance.[68]

Ivanti Neurons Platform

The Ivanti Neurons Platform is a cloud-native, AI-powered technology platform designed to enhance IT operations by providing visibility, automation, and security across endpoints, networks, and services. Announced on July 21, 2020, it functions as a hyper-automation foundation that enables proactive self-healing of devices, predictive security measures, and autonomous self-service for users, aiming to reduce operational risks and costs.[69] The platform integrates artificial intelligence, machine learning, and analytics to detect events passively and proactively, offering IT teams insights into device performance and potential vulnerabilities without requiring constant manual intervention.[4][70] Core capabilities include unified endpoint management, which supports optimization of resources by resolving issues in real-time without user disruption, and integrated vulnerability prioritization for faster remediation.[71][72] It encompasses modular solutions such as Ivanti Neurons for ITSM, which streamlines help desk functions and service management; Ivanti Neurons for MDM, handling devices across iOS, Android, macOS, Windows, and others; and extensions for application control to block unauthorized software and mitigate zero-day threats.[65][73][74] Additional features cover IT service management, zero trust access, and industrial IoT security, with recent updates in 2025.1 incorporating sentiment analysis from employee surveys to inform IT strategies.[4][75] The platform emphasizes agent and user experiences through connected workflows, leveraging data from across IT environments to automate responses and harden security postures.[24] For instance, it supports remote attestation and blocking of malware via application controls, while maintaining data security standards like AES-256 encryption for stored information.[74][76] Expansions since launch have included network security and compliance modules, such as Ivanti Neurons for PPM and GRC, released in October 2021, to address productivity and governance needs.[77] The platform supports Zero Trust Identity elements through integrations with identity providers, passwordless authentication via Ivanti Zero Sign-On (using device-as-identity and biometrics), and attribute-based access controls. These complement nZTA by incorporating real-time device health and user signals into access decisions, though Ivanti also offers separate tools like Identity Director for identity governance and administration (IGA).

Ivanti Neurons for Zero Trust Access

Ivanti Neurons for Zero Trust Access (nZTA or ZTA) is a SaaS-delivered Zero Trust Network Access (ZTNA) solution within the Ivanti Neurons platform. Launched around 2021, it replaces or augments traditional VPNs with a modern zero-trust approach emphasizing "never trust, always verify." It provides secure, context-aware connectivity to applications across on-premises, cloud, and hybrid environments. Key features include:
  • Continuous verification of user identity, device posture, and contextual risk factors before granting access.
  • Granular, conditional least-privilege access controls, dynamically enforced in real-time.
  • Software-defined perimeter that hides applications ("dark cloud") to minimize attack surface and prevent lateral movement.
  • Direct-to-application connections avoiding traffic hairpinning for improved performance.
  • Hybrid/multi-cloud support, compatible standalone or with existing VPNs for phased adoption.
  • Centralized policy orchestration, visibility into access patterns, anomalies, and analytics.
nZTA integrates with existing identity systems (e.g., Active Directory, Microsoft Entra ID) for authentication, supporting MFA and conditional access. It complements with passwordless authentication via Ivanti Zero Sign-On (ZSO), device-as-identity, biometrics, and derived credentials. Device posture from Ivanti's UEM/MDM feeds into access decisions. The solution aligns with NIST Zero Trust Architecture principles, contributing to NCCoE reference implementations by providing policy enforcement, decision, and information points. Partnerships, such as with Lookout in 2022, extended capabilities with CASB and SWG for enhanced threat prevention and data security. Strengths include hybrid flexibility, user experience, and integration with Ivanti's endpoint ecosystem. Limitations involve lighter standalone advanced IAM/IGA compared to specialized providers, with reliance on ecosystem integrations. For more, see Ivanti's official product page: https://www.ivanti.com/products/ivanti-neurons-zero-trust-access

Security Incidents

2021 Pulse Connect Secure Breach

In April 2021, a critical zero-day vulnerability (CVE-2021-22893) in Pulse Connect Secure VPN appliances, affecting versions 9.0R3 and higher, was actively exploited by threat actors, enabling unauthenticated remote code execution via an authentication bypass in the Windows File Share Browser component.[78][79] Exploitation evidence dated back to at least March 31, 2021, with attackers chaining the flaw alongside older, unpatched vulnerabilities such as CVE-2019-11510 to gain initial access, exfiltrate data, and deploy web shells for persistence.[80] Pulse Secure issued an out-of-band patch on April 20, 2021, after detecting limited customer compromises, urging immediate upgrades to mitigate risks of arbitrary file execution and network pivoting.[81] The incident compromised numerous organizations, including at least five U.S. federal civilian agencies, defense contractors, and financial institutions, with attackers suspected to be Chinese state-sponsored groups seeking espionage rather than ransomware or destruction.[82][80] CISA and the vendor (then Pulse Secure, later integrated into Ivanti) collaborated to assist affected entities, issuing alerts on indicators of compromise like command-and-control traffic to domains mimicking legitimate services.[80][83] No public disclosure quantified total victims, but advisories from agencies like HHS highlighted active campaigns targeting healthcare and critical infrastructure via these flaws.[84] Response efforts emphasized rapid patching and vulnerability scanning, with international bodies like the UK's NCSC and Canada's CCCS confirming widespread exploitation attempts and recommending network segmentation to limit lateral movement post-breach.[85][83] The event underscored persistent risks from unpatched VPN endpoints, contributing to heightened scrutiny of Pulse products' security posture ahead of Ivanti's 2022 acquisition of the Pulse Secure business.[80]

2023-2024 Vulnerability Exploits

In January 2024, Ivanti disclosed two zero-day vulnerabilities affecting Ivanti Connect Secure (ICS) and Ivanti Policy Secure gateways: CVE-2023-46805, an authentication bypass flaw in the web management interface, and CVE-2024-21887, a command injection vulnerability that could enable remote code execution when chained with the former.[86] Exploitation of these flaws required no authentication and allowed attackers to craft malicious requests, leading to unauthorized access and potential persistence via web shells.[87] Threat actors began actively exploiting them in the wild as early as December 2023, with over 600 confirmed compromises observed by security researchers by mid-2024.[88] The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory on February 29, 2024, warning of ongoing exploitation by multiple threat actors, including those associated with Chinese state-sponsored groups, and added the vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating federal agencies to patch or disconnect affected systems by March 28, 2024.[89] Ivanti recommended immediate application of integrity checks, factory resets for compromised devices, and upgrades to patched versions (ICS 9.1R19.5, 22.1R5.2, or higher; Policy Secure 9.1R19.1 or 22.1R1), along with monitoring for indicators of compromise such as anomalous logs or unauthorized files.[90] Additional related flaws, including CVE-2024-21888 (another auth bypass), CVE-2024-21893 (out-of-bounds read), and CVE-2024-22024 (information disclosure), were also disclosed in early 2024 and exploited in tandem, amplifying risks to unpatched gateways used for remote access.[88][89] Exploitation tactics often involved chaining CVE-2023-46805 for initial access followed by CVE-2024-21887 for command execution, enabling attackers to deploy webshells, exfiltrate data, or establish backdoors, as detailed in analyses from firms like Rapid7 and Akamai.[91][92] Ivanti's response included enhanced logging and mitigation scripts, but critics noted delays in detection, with some appliances remaining vulnerable due to incomplete patching across legacy versions.[86] By April 2024, Ivanti reported mitigating the issues through updated advisories, though widespread scanning and exploitation persisted into mid-2024, underscoring risks in network edge devices.[93][9]

2025 Zero-Day Attacks and Responses

In early 2025, Ivanti disclosed and patched multiple zero-day vulnerabilities in its Connect Secure VPN appliances, which were actively exploited by threat actors for remote code execution (RCE). On January 8, 2025, Ivanti addressed CVE-2025-0282, a stack-based buffer overflow allowing unauthenticated remote attackers to execute arbitrary code on affected systems, with exploitation observed as early as December 2024.[94] Ivanti recommended immediate patching and integrity checks, while the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued alerts urging federal agencies to apply mitigations due to confirmed in-the-wild activity.[95] In April 2025, Ivanti revealed another critical zero-day, CVE-2025-22457, affecting Connect Secure versions up to 22.7R2.5, enabling RCE via unauthenticated access and linked to suspected China-nexus threat actors.[96] The vulnerability was patched on April 3, 2025, with Ivanti advising customers to update firmware, rotate credentials, and monitor for anomalous activity; Google Mandiant reported post-exploitation persistence tactics including backdoor deployment.[97] May 2025 saw exploitation of a chained vulnerability pair in Ivanti Endpoint Manager Mobile (EPMM) versions 12.5.0.0 and earlier: CVE-2025-4427 (authentication bypass) and CVE-2025-4428 (command injection), together allowing unauthenticated RCE.[98] Ivanti issued patches on May 13, 2025, confirming limited breaches and recommending full system reboots and log reviews; CISA added the flaws to its Known Exploited Vulnerabilities catalog on May 14, mandating remediation by federal entities within weeks.[99] Threat actors, including those with China-nexus indicators, deployed malware like malicious listeners post-exploitation, prompting advisories from the UK's NCSC and NHS Digital.[100][101] Later in 2025, attackers leveraged Ivanti flaws to deploy MDifyLoader malware, an in-memory loader facilitating further payload execution, as detailed in July disclosures; Ivanti's response included enhanced detection tooling in its security advisories.[102] By September, CISA warned of two malware strains exploiting the EPMM chain around May 15, emphasizing the need for multi-factor authentication and network segmentation beyond patching.[103] Ivanti's repeated zero-day incidents drew scrutiny for product hardening, though the company maintained that timely updates mitigated risks when applied promptly.[104] In 2025, Ivanti addressed multiple vulnerabilities in Endpoint Manager (EPM), including high-severity flaws patched in releases such as EPM 2024 SU5 (fixing issues disclosed in October) and SU4 SR1 (addressing CVE-2025-10573, a critical unauthenticated stored XSS with CVSS 9.6, enabling potential session hijacking). Additional patches covered SQL injection, improper encryption, and other risks in EPM versions, with no evidence of wild exploitation for some but emphasizing timely updates. These build on prior gateway-focused incidents, highlighting continued focus on securing management platforms.

Product Security and PSIRT

Ivanti maintains a Product Security Incident Response Team (PSIRT) to handle vulnerability identification, assessment, patching, disclosure, and communication. The team operates under a formal Vulnerability Disclosure Policy (version 2.1, July 2025), which encourages responsible reporting from security researchers. Reports are submitted via [email protected] (with optional PGP encryption) or a Bugcrowd-powered form. The policy covers Ivanti products, services, and infrastructure, excluding DoS, physical/social engineering, and unapproved testing. Ivanti validates reports within 10 business days, prioritizes by severity, reserves CVEs for CVSS 4.0+, and provides at least 120 days before public disclosure by reporters. It operates an invitation-only bug bounty on Bugcrowd for select products. Ivanti releases security patches predictably on the second Tuesday of each month to aid customer planning. Recent enhancements include intensified internal scanning, manual exploitation testing, and responsible disclosure process improvements. Tools like the Integrity Checker Tool (ICT) and newer assurance utilities help detect compromises, particularly in Connect Secure. While Ivanti's PSIRT has formal processes, including a structured Vulnerability Disclosure Policy, predictable monthly patch releases, and recent improvements such as intensified scanning and manual testing, the frequency of severe, exploited zero-day vulnerabilities—particularly in high-exposure edge products like Connect Secure and Endpoint Manager Mobile—has drawn criticism for gaps in secure development practices and rapid response capabilities. These persistent issues have contributed to ongoing risks despite available patches and tools, damaged trust among customers and security professionals, and led to government mandates, including multiple CISA emergency directives requiring federal agencies to mitigate, disconnect, or rebuild affected systems.

Reception and Impact

Achievements and Innovations

Ivanti's Ivanti Neurons platform introduced AI-powered automation for IT service management, patch deployment, and vulnerability remediation, enabling self-healing endpoints and predictive risk prioritization across hybrid environments.[2] In July 2025, enhancements to the platform added AI-driven localization for global deployments, auto-ticketing integrations with tools like Microsoft Azure DevOps, and accelerated asset scanning to improve operational efficiency.[50] These updates build on the platform's core innovation of aggregating telemetry data from devices and networks to automate remediation workflows, reducing manual intervention in endpoint security.[24] A key advancement in network security came with the September 30, 2025, release of Ivanti Connect Secure version 25.X, which incorporated modern operating system compatibility, SELinux enforcement for enhanced kernel protections, and rearchitected components to bolster VPN resilience against exploits.[105] This iteration addressed prior architectural limitations by prioritizing secure-by-default configurations and performance optimizations, setting benchmarks for enterprise VPN deployments.[106] Ivanti's solutions have garnered recognition for these developments, with Ivanti Neurons for ITSM awarded the 2025 Future of Work Product of the Year for its automation capabilities in service desk operations.[51] Ivanti Neurons for Patch Management received a 2025 Stratus Award for Cloud Computing on October 2, 2025, highlighting its cloud-native innovation in third-party patching and deployment speed.[52] Additionally, Ivanti Neurons for External Attack Surface Management earned a Bronze award in the Cyber Exposure Management category at the 20th Annual 2025 Globee Awards, acknowledging its visibility into external assets and risk scoring.[107] Earlier, in 2021, Ivanti secured 11 MUSE Creative Awards for its Everywhere Workplace brand launch, which emphasized edge-to-cloud asset unification.[108]

Criticisms and Security Track Record

Ivanti has encountered substantial criticism for its security track record, characterized by a pattern of critical vulnerabilities in its networking and endpoint management products that have been repeatedly exploited by nation-state actors and cybercriminals. From 2021 onward, Ivanti gateways—particularly those inherited from the Pulse Secure acquisition—have been prime targets, with at least 16 known exploited vulnerabilities since 2024, exceeding other vendors in the network edge device category according to Known Exploited Vulnerabilities (KEV) catalog data.[10] This frequency has prompted accusations of systemic deficiencies in secure-by-design practices, with experts questioning whether Ivanti's issues reflect broader challenges in legacy VPN architectures or company-specific engineering lapses.[104] A notable escalation occurred in early 2024, when U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive mandating federal agencies to disconnect vulnerable Ivanti Connect Secure and Policy Secure gateways within 48 hours due to active exploitation of zero-day flaws like CVE-2024-21887 (an authentication bypass) and CVE-2024-21893 (a command injection).[89][109] These attacks, linked to Chinese state-sponsored groups, enabled unauthorized access, data exfiltration, and webshell implantation, affecting defense contractors and government entities. Similar chains persisted into 2025, including exploits of CVE-2025-4428 in Endpoint Manager Mobile for remote code execution and CVE-2025-22457 in VPN products by espionage actors.[101][10] Critics, including cybersecurity firms like Palo Alto Networks' Unit 42, have highlighted Ivanti's delayed patching and insufficient mitigation guidance as exacerbating factors, with observed exploits involving backdoor implants and lateral movement tools like Cobalt Strike.[110] In October 2025, disclosure of 13 unpatched zero-days in Endpoint Manager further fueled concerns, including an insecure deserialization flaw (CVE-2025-11622) allowing remote code execution.[111] Ivanti responded by pledging process overhauls and enhanced bounties, but ongoing incidents—seven exploited flaws by mid-2025—have eroded trust among enterprise users reliant on its exposure management tools.[104] Beyond security, anecdotal reports from IT administrators cite unreliable remote management in legacy products, though these lack widespread empirical validation.[112] Overall, the track record underscores vulnerabilities in perimeter-focused architectures amid rising zero-trust scrutiny, positioning Ivanti as a cautionary case for vendors slow to adapt.

Market Position and Competitive Landscape

Ivanti holds a leadership position in the IT service management (ITSM) software market, as recognized by the IDC MarketScape: Worldwide IT Service Management Software 2024 Vendor Assessment, where it was named a Leader for its strategic execution and capabilities in delivering value through platforms like Ivanti Neurons for ITSM.[113] The global ITSM applications market reached $11.4 billion in 2024, growing at a compound annual growth rate (CAGR) of approximately 6.2% toward $15.4 billion by 2029, with Ivanti competing as a top-tier vendor amid this expansion driven by demand for integrated IT operations and security.[114] In IT asset management (ITAM), Ivanti's Neurons platform garners positive reviews for asset consolidation and compliance, though the broader ITAM market is projected at $2.09 billion in 2025 with a 6.32% CAGR to $2.85 billion by 2030, where Ivanti maintains a niche but not dominant share.[115][116] Financially, Ivanti faced headwinds in 2024, with revenue declining about 4.5% in the first half of its fiscal year due to a shift from perpetual licenses to subscription models, impacting EBITDA and free cash flow.[117] This transition, coupled with liquidity concerns, led to credit rating downgrades by Fitch to 'C' in May 2025 following a debt exchange announcement and further to 'RD' amid ongoing pressures, reflecting challenges in maintaining market momentum despite product strengths.[118][29] In the competitive landscape, Ivanti contends with established players across endpoint management, secure access, and ITSM domains. Key rivals in endpoint management include Microsoft Intune, VMware Workspace ONE, and Cisco Meraki, which offer robust unified endpoint solutions often integrated with broader ecosystems.[119] For secure access and zero-trust networking, competitors such as Cisco Secure Client, Fortinet, and Palo Alto Networks provide alternatives emphasizing vulnerability management and threat prevention.[120] In ITSM, ServiceNow dominates with comprehensive workflow automation, while others like ManageEngine Endpoint Central and SolarWinds challenge Ivanti on cost-effective asset and service desks.[121] Ivanti differentiates through its Neurons platform's focus on AI-driven automation and security-IT convergence, but faces pressure from larger incumbents with deeper market penetration and resources.[122]

References

User Avatar
No comments yet.