logo

Eliminate VPN vulnerabilities with Cloudflare One

ID: 5eff38fe-1ed7-5f86-a18c-c40c1ca3001e

STIX ID: report--5eff38fe-1ed7-5f86-a18c-c40c1ca3001e

Feed Name: Cloudflare Blog

Threat Score
90/100

Date Published: 2024-03-06

Date Updated: 2026-04-27

Author: Dan Hall

...
...

On January 2024 CISA issued an emergency directive after active exploitation of two chained zero-day vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure appliances enabled unauthenticated RCE; attackers harvested credentials, deployed web shells, reversed tunneled to C2, and disabled logging. The report summarizes the technical details (CVE-2023-46805 and CVE-2024-21887), the operational impact on networks and legacy VPN architectures, and advocates replacing/augmenting VPNs with Zero Trust SASE controls such as Cloudflare One to reduce blast radius and remove exposure to appliance internals.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.