logo

Ivanti warns of three more CSA zero-days exploited in attacks

ID: 0f1f9bd1-a2c6-5a1d-addd-86bdde9872b4

STIX ID: report--0f1f9bd1-a2c6-5a1d-addd-86bdde9872b4

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-10-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti disclosed three new actively exploited zero-day vulnerabilities in its Cloud Services Appliance (CSA) that can be chained with a prior admin-bypass flaw to enable SQL injection, command injection (remote code execution), and path traversal; customers are urged to upgrade to CSA 5.0.2, rebuild any suspected compromised appliances, and monitor EDR alerts and admin account changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.