logo

Ivanti Keeps Security Teams Scrambling With 2 More Vulns

ID: 79d607d0-6738-5647-9512-e30d45257f6b

STIX ID: report--79d607d0-6738-5647-9512-e30d45257f6b

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-03-21

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Ivanti disclosed two critical vulnerabilities—a remote code execution bug in Standalone Sentry (CVE-2023-41724, CVSS 9.6) and an authenticated remote file-write/RCE in Neurons for ITSM (CVE-2023-46808, CVSS 9.9)—and published fixes; the vendor reported no evidence of active exploitation for these two issues. The report highlights a broader pattern of frequent, severe Ivanti vulnerabilities and prior rapid exploitation by actors such as Magnet Goblin and UNC5221, underscoring elevated risk for affected customers until patches are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.