logo

Ivanti warns of another critical CSA flaw exploited in attacks

ID: 5335d947-9817-57aa-b713-03697c019a8f

STIX ID: report--5335d947-9817-57aa-b713-03697c019a8f

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-09-19

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti warned that threat actors are exploiting a path-traversal admin-bypass (CVE-2024-8963) in Cloud Services Appliance, often chained with a high-severity command-injection bug (CVE-2024-8190) to bypass authentication and execute arbitrary commands on unpatched appliances; CISA added both CVEs to its Known Exploited Vulnerabilities catalog and federal agencies must patch quickly, while Ivanti recommends patch 519, rebuilding compromised appliances, and moving to CSA 5.0 where possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.