logo

CISA Adds High-Severity Ivanti Vulnerability to KEV Catalog

ID: 6b32dc91-8f77-5633-bd04-3b16e5d48dbc

STIX ID: report--6b32dc91-8f77-5633-bd04-3b16e5d48dbc

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-10-03

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

A critical SQL injection vulnerability (CVE-2024-29824) in Ivanti Endpoint Manager (core server) allows unauthenticated attackers on the network to achieve arbitrary code execution; it has a CVSS score of 9.6 and Ivanti reported a limited number of customers were exploited in the wild. Ivanti released security updates and guidance for patching, and the advisory urges organizations to prioritize immediate patching and thorough security assessments to mitigate potential compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.