logo

Ivanti devices hit by wave of exploits for latest security hole

ID: 031f281f-0a11-5b58-9c70-5cb86777acc5

STIX ID: report--031f281f-0a11-5b58-9c70-5cb86777acc5

Feed Name: The Register (Security)

Threat Score

Date Published: 2024-02-05

Date Updated: 2026-04-26

Author: Jessica Lyons Hardcastle

...
...

Multiple threat actors are exploiting Ivanti’s CVE-2024-21893 SSRF flaw in Connect Secure and Policy Secure appliances, which can be chained with CVE-2024-21887 for unauthenticated root-level command injection, compounding prior issues with CVE-2023-46805. Following Rapid7’s public PoC, ShadowServer observed widespread exploitation and backdoor attempts from over 170 IPs. Ivanti has released patches for supported versions, while CISA issued an emergency directive requiring federal agencies to disconnect the affected products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.