logo

Ivanti warns high severity CSA flaw is now exploited in attacks

ID: a15399f1-75de-538f-9764-490ea1c79839

STIX ID: report--a15399f1-75de-538f-9764-490ea1c79839

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-09-13

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti disclosed CVE-2024-8190, a high-severity command-injection RCE in Cloud Service Appliance (CSA) 4.6 that is actively being exploited against a limited set of customers; CISA has added the flaw to its Known Exploited Vulnerabilities catalog and directed federal agencies to patch by October 4. Ivanti urges customers to upgrade to CSA 5.0 (CSA 4.6 is EOL), review administrative access and broker logs, and check EDR alerts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.