logo

Security alert: Ivanti Connect Secure and Policy Secure zero-day vulnerabilities

ID: d0124698-b099-5258-bb73-e40477b90856

STIX ID: report--d0124698-b099-5258-bb73-e40477b90856

Feed Name: Expel Blog

Threat Score
90/100

Date Published: 2024-03-01

Date Updated: 2026-04-27

Author: Aaron Walton

...
...

CISA warns that threat actors are actively exploiting zero-day vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure Gateway appliances, potentially allowing unauthorized access, credential theft, and rootkit-level persistence that can evade detection. Organizations are urged to apply Ivanti patches, run integrity checks, restrict SSL VPN outbound access and privileges, hunt for IOCs, and assume affected devices may be compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.