logo

Ivanti discloses fifth vulnerability, doesn't credit researchers who found it

ID: 9682b9c2-84e3-54da-82e8-926640667900

STIX ID: report--9682b9c2-84e3-54da-82e8-926640667900

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-02-09

Date Updated: 2026-04-26

Author: Connor Jones

...
...

**Executive summary:** The article details a string of vulnerabilities in Ivanti Connect Secure, Policy Secure, and ZTA gateways—including CVE-2024-22024 and multiple earlier zero-days—that have prompted mitigations, staged patching, reports of active exploitation and mass exploitation concerns (with estimates of devices potentially backdoored), and emergency advisories from CISA and the UK's NCSC; it also notes a dispute between Ivanti and external researchers over discovery credit.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.