logo

3 More Ivanti Cloud Vulns Exploited in the Wild

ID: 6280513c-91b4-5456-bb51-5200a2452643

STIX ID: report--6280513c-91b4-5456-bb51-5200a2452643

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2024-10-09

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

Ivanti has disclosed three additional vulnerabilities in its Cloud Services Appliance (CVE-2024-9379, CVE-2024-9380, CVE-2024-9381) that are being chained with a previously reported zero-day (CVE-2024-8963) and observed in limited exploitation; issues include remote-authenticated SQL execution, OS command injection enabling RCE with admin privileges, and path traversal affecting CSA versions prior to 5.0, with vendor guidance to review administrative users/EDR alerts and to rebuild to version 5.0 if compromise is suspected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.