Ivanti: Patch new Connect Secure auth bypass bug immediately
ID: 13d78c63-44f2-58cc-a909-5dfe9813773a
STIX ID: report--13d78c63-44f2-58cc-a909-5dfe9813773a
Feed Name: Bleeping Computer
Ivanti warned of a critical authentication-bypass XXE vulnerability (CVE-2024-22024) affecting Connect Secure, Policy Secure, and ZTA gateways that—alongside other actively exploited zero-days (CVE-2023-46805, CVE-2024-21887, CVE-2024-21893)—has led to mass targeting and compromises of thousands of Internet-exposed appliances; Ivanti released patches and mitigations (including recommended factory resets) and CISA ordered federal agencies to disconnect vulnerable devices immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
