logo

Ivanti Researchers Report Two Critical Zero-Day Vulnerabilities

ID: bcea7af5-761b-56c7-8177-45eb17d5b7bd

STIX ID: report--bcea7af5-761b-56c7-8177-45eb17d5b7bd

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-01-11

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

Ivanti disclosed two actively exploited zero‑day vulnerabilities impacting Ivanti Connect Secure and Ivanti Policy Secure gateways: CVE-2023-46805 (authentication bypass, CVSS 8.2) and CVE-2024-21887 (authenticated command injection, CVSS 9.1). Mitigations are available from the vendor while patches are being released in waves (auth bypass patch due Jan 22; command injection patch due Feb 19); customers are urged to apply mitigations immediately and contact Ivanti Support for assistance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.