logo

Critical Ivanti vTM auth bypass bug now exploited in attacks

ID: 662c2cb9-be8a-50a7-9e84-63083fe53951

STIX ID: report--662c2cb9-be8a-50a7-9e84-63083fe53951

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-09-24

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti vTM has a critical authentication-bypass vulnerability (CVE-2024-7593) that can let unauthenticated attackers create admin accounts; public PoC exists and CISA has marked it as actively exploited in its KEV catalog, so organizations should apply patches, check audit logs for new 'user1'/'user2' admin accounts, and restrict exposure of the management interface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.