Ivanti Researchers Report Two Critical Zero-Day Vulnerabilities
ID: bcea7af5-761b-56c7-8177-45eb17d5b7bd
STIX ID: report--bcea7af5-761b-56c7-8177-45eb17d5b7bd
Feed Name: Dark Reading
Date Published: 2024-01-11
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Ivanti disclosed two actively exploited zero‑day vulnerabilities impacting Ivanti Connect Secure and Ivanti Policy Secure gateways: CVE-2023-46805 (authentication bypass, CVSS 8.2) and CVE-2024-21887 (authenticated command injection, CVSS 9.1). Mitigations are available from the vendor while patches are being released in waves (auth bypass patch due Jan 22; command injection patch due Feb 19); customers are urged to apply mitigations immediately and contact Ivanti Support for assistance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
