Ivanti Keeps Security Teams Scrambling With 2 More Vulns
ID: 79d607d0-6738-5647-9512-e30d45257f6b
STIX ID: report--79d607d0-6738-5647-9512-e30d45257f6b
Feed Name: Dark Reading
Ivanti disclosed two critical vulnerabilities—a remote code execution bug in Standalone Sentry (CVE-2023-41724, CVSS 9.6) and an authenticated remote file-write/RCE in Neurons for ITSM (CVE-2023-46808, CVSS 9.9)—and published fixes; the vendor reported no evidence of active exploitation for these two issues. The report highlights a broader pattern of frequent, severe Ivanti vulnerabilities and prior rapid exploitation by actors such as Magnet Goblin and UNC5221, underscoring elevated risk for affected customers until patches are applied.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
