logo

Ivanti warns of new Connect Secure zero-day exploited in attacks

ID: 3113e57e-8560-5ee7-8ad7-18b2ca5babdc

STIX ID: report--3113e57e-8560-5ee7-8ad7-18b2ca5babdc

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-01-31

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti disclosed multiple critical vulnerabilities affecting Connect Secure, Policy Secure, and ZTA gateways — including an actively exploited SAML SSRF zero-day (CVE-2024-21893) and other flaws (CVE-2023-46805, CVE-2024-21887, CVE-2024-21888) that allow authentication bypass, command injection, and privilege escalation; attackers have chained these to mass-exploit hundreds of internet-exposed appliances and deploy custom malware, cryptominers, and persistent backdoors, prompting patches, mitigations, and a CISA emergency directive.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.