logo

Ivanti fixes VPN gateway vulnerability allowing RCE, DoS attacks

ID: 14a0b179-ea0e-5023-b2cc-42bd20182c26

STIX ID: report--14a0b179-ea0e-5023-b2cc-42bd20182c26

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-04-03

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti has released patches for multiple high-severity vulnerabilities in Connect Secure and Policy Secure gateways — including CVE-2024-21894, an unauthenticated heap overflow that can enable remote code execution — while thousands of Internet-exposed appliances remain vulnerable. The report cites large device counts via Shodan/ShadowServer, prior nation-state exploitation of Ivanti zero-days, CISA emergency directives to secure or disconnect affected appliances, and guidance to apply vendor patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.