logo

Ivanti Connect Secure/Policy Secure CVE-2023-46805, CVE-2024-21887 Combine for Unauthenticated RCE, and following CVEs discovered over time

ID: 106b15de-4a2b-50e0-9d15-84ac27c7b291

STIX ID: report--106b15de-4a2b-50e0-9d15-84ac27c7b291

Feed Name: Kudelski Security

Threat Score
90/100

Date Published: 2024-01-11

Date Updated: 2026-07-22

...
...

Kudelski Security reports multiple critical vulnerabilities in Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA (including CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893, and CVE-2024-22024) that enable authentication bypass, command injection, privilege escalation, SSRF, and XXE; the flaws impact supported 9.x and 22.x releases, have high CVSS scores, and are being actively exploited by a state-sponsored APT and opportunistic actors, so immediate patching or application of Ivanti's XML mitigation is strongly recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.