Ivanti fixes critical Standalone Sentry bug reported by NATO
ID: 11b3ff97-f8e3-5687-aafb-c3afc4ae5d17
STIX ID: report--11b3ff97-f8e3-5687-aafb-c3afc4ae5d17
Feed Name: Bleeping Computer
Ivanti issued emergency patches for two critical vulnerabilities—CVE-2023-41724 (Remote Code Execution in Standalone Sentry) and CVE-2023-46808 (Authenticated remote file write in Neurons for ITSM)—that can allow attackers to execute commands; cloud instances are patched but on-premises installations remain vulnerable. The report highlights previous nation-state exploitation and large-scale abuse of other Ivanti zero-days (prompting CISA emergency directives), recommends immediate patching, and notes Ivanti has found no evidence these two specific flaws are yet exploited in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
