logo

Critical Ivanti RCE flaw with public exploit now used in attacks

ID: 6347254e-03af-5095-a10c-55e01f798edc

STIX ID: report--6347254e-03af-5095-a10c-55e01f798edc

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-10-02

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

A critical SQL injection vulnerability (CVE-2024-29824) in Ivanti Endpoint Manager's Core server enables unauthenticated attackers on the same network to achieve remote code execution; Horizon3.ai published a proof-of-concept and Ivanti confirmed limited in-the-wild exploitation, prompting CISA to add the flaw to its Known Exploited Vulnerabilities catalog and require federal agencies to patch vulnerable appliances promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.