logo

Dual Zero-Day Threats in Ivanti Connect Secure and Policy Secure Gateways – CVE-2023-46805 and CVE-2024-21887 

ID: 35701b83-ad7a-5b4e-bff2-4188fb84530e

STIX ID: report--35701b83-ad7a-5b4e-bff2-4188fb84530e

Feed Name: Qualys Blog

Threat Score
90/100

Date Published: 2024-01-11

Date Updated: 2026-04-28

Author: Saeed Abbasi

...
...

Two zero-day vulnerabilities in Ivanti Connect Secure and Policy Secure Gateways—CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection)—are being actively exploited in the wild, and when chained can allow unauthenticated remote code execution; CISA has added them to its Known Exploited Vulnerabilities catalog, Ivanti has issued mitigations while patches are developed, and Qualys has released detection QIDs to help organizations scan and remediate affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.