logo

Ivanti: Patch new Connect Secure auth bypass bug immediately

ID: 13d78c63-44f2-58cc-a909-5dfe9813773a

STIX ID: report--13d78c63-44f2-58cc-a909-5dfe9813773a

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-02-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti warned of a critical authentication-bypass XXE vulnerability (CVE-2024-22024) affecting Connect Secure, Policy Secure, and ZTA gateways that—alongside other actively exploited zero-days (CVE-2023-46805, CVE-2024-21887, CVE-2024-21893)—has led to mass targeting and compromises of thousands of Internet-exposed appliances; Ivanti released patches and mitigations (including recommended factory resets) and CISA ordered federal agencies to disconnect vulnerable devices immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.