logo

Ivanti urges customers to patch yet another critical vulnerability

ID: 05efd3e7-8a20-5bae-9d52-7c9217f4d141

STIX ID: report--05efd3e7-8a20-5bae-9d52-7c9217f4d141

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2024-02-09

Date Updated: 2026-04-28

...
...

Ivanti disclosed an XXE vulnerability (CVE-2024-22024, CVSS 8.3) in specific versions of Connect Secure, Policy Secure, and ZTA gateways that can allow access to restricted resources without authentication; patches and detailed KB mitigation instructions are available for supported versions and customers are urged to apply them immediately. Ivanti reports no evidence of exploitation of this CVE to date, but multiple other Ivanti vulnerabilities have been actively exploited, and CISA previously advised disconnecting vulnerable Ivanti products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.