logo

CISA cautions against using hacked Ivanti VPN gateways even after factory resets

ID: 5c73b77b-28ab-5e32-9708-d258c876fbca

STIX ID: report--5c73b77b-28ab-5e32-9708-d258c876fbca

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-02-29

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

**CISA advisory:** Multiple high-to-critical Ivanti Connect Secure and Policy Secure VPN vulnerabilities (including CVE-2023-46805, CVE-2024-21887, CVE-2024-22024, CVE-2024-21893) are being actively exploited to achieve authentication bypass, command injection, SSRF, and arbitrary command execution; attackers have been shown to gain root persistence that can survive factory resets and evade Ivanti's Integrity Checker Tool, leading CISA to advise aggressive remediation, hunting for IOCs, and order federal agencies to disconnect affected appliances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.