logo

CISA orders federal agencies to disconnect Ivanti VPN appliances by Saturday

ID: f7d637dd-f7d8-530d-abbb-d43b822bea01

STIX ID: report--f7d637dd-f7d8-530d-abbb-d43b822bea01

Feed Name: Bleeping Computer

Threat Score
95/100

Date Published: 2024-02-01

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA has ordered U.S. federal agencies to disconnect all Ivanti Connect Secure and Ivanti Policy Secure VPN appliances by Feb 2 due to multiple actively exploited zero-day vulnerabilities (CVE-2023-46805, CVE-2024-21887, CVE-2024-21893). The report describes widespread exposure (Shodan: ~22,000; Shadowserver: ~21,400), evidence of compromised devices, Ivanti patches and mitigations, and guidance to factory reset, rebuild with patched software, revoke credentials, and assume linked accounts may be compromised.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.