logo

Ivanti: VPN appliances vulnerable if pushing configs after mitigation

ID: b8c621cd-7e25-5920-8d9d-0b57a0a31026

STIX ID: report--b8c621cd-7e25-5920-8d9d-0b57a0a31026

Feed Name: Bleeping Computer

Threat Score
95/100

Date Published: 2024-01-22

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Ivanti warned that two actively exploited zero-days in Connect Secure and Policy Secure (an authentication bypass and a command-injection flaw) are being chained in large-scale attacks; thousands of appliances are internet-exposed, hundreds have been compromised, and at least one suspected state-backed group (UTA0178/UNC5221) has backdoored over 2,100 devices with webshells and deployed miners and custom malware, prompting mitigations and a CISA emergency directive.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.