logo

Ivanti Zero-Day Exploits Skyrocket Worldwide; No Patches Yet

ID: 8c714224-c7cd-5c70-8648-300fc246e313

STIX ID: report--8c714224-c7cd-5c70-8648-300fc246e313

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-01-16

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Ivanti Connect Secure VPNs are being actively exploited using two unpatched zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887) that together enable authentication bypass and arbitrary command execution; a suspected Chinese state-aligned group (UTA0178) has deployed a web shell named "GiftedVisitor," and scans have identified thousands of compromised devices worldwide. Ivanti has published mitigations and an Integrity Checker tool, but full patches are not yet available and organizations are urged to follow incident response playbooks to isolate and investigate affected systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.