logo

CISA adds fresh Ivanti vuln, critical Fortinet bug to hall of shame

ID: 03936b29-a703-5a0d-99d0-9baadaf30d7f

STIX ID: report--03936b29-a703-5a0d-99d0-9baadaf30d7f

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2024-10-10

Date Updated: 2026-04-26

Author: Connor Jones

...
...

The article reports that CISA has added multiple actively exploited vulnerabilities to its KEV catalog: a critical Fortinet format-string RCE (CVE-2024-23113) impacting FortiOS, FortiPAM, FortiProxy, and FortiWeb, and several Ivanti CSA flaws (SQLi, command injection and path traversal) being exploited—notably against EOL CSA 4.6. Vendors recommend immediate patching or mitigations (removing fgfm access for Fortinet, rebuilding Ivanti appliances to 5.0.2) and additional protections such as EDR and restrictive policies while investigations continue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.