logo

Ivanti releases patches for VPN zero-days, discloses two more high-severity vulns

ID: c18fd9cc-d71b-5126-8724-9e496ed67b18

STIX ID: report--c18fd9cc-d71b-5126-8724-9e496ed67b18

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-01-31

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Ivanti released patches and updated mitigations for multiple high-severity vulnerabilities in Connect Secure, Policy Secure, and ZTA gateways, including two newly disclosed zero-days (CVE-2024-21888 privilege escalation and CVE-2024-21893 SSRF). Security researchers and CISA report active exploitation, mitigation bypasses, credential capture and webshell deployment in targeted networks; Ivanti and CISA urge urgent patching, factory resets, and proactive threat hunting while additional patches are rolled out.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.