logo

Ivanti patches exploited admin command execution flaw

ID: 03ee4049-5d2a-5eae-85e5-4713118de81e

STIX ID: report--03ee4049-5d2a-5eae-85e5-4713118de81e

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-09-20

Date Updated: 2026-04-26

Author: Connor Jones

...
...

CISA added Ivanti CSA CVE-2024-8963 (path traversal, CVSS 9.4) to its KEV catalog after limited customer exploitation was observed; the bug can expose restricted functionality and, if chained with an earlier command-injection flaw (CVE-2024-8190), enable administrative command execution. Ivanti has released a patch (last backport for 4.6) and urges affected customers to patch or upgrade to 5.0, review broker logs/EDR for signs of compromise, and rebuild impacted appliances if intrusion is detected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.