logo

Cyble Sensors Detect Exploitation Of Ivanti Vulnerabilities

ID: 500396c3-8b45-5ec5-8077-afdd817cadab

STIX ID: report--500396c3-8b45-5ec5-8077-afdd817cadab

Feed Name: Cyble Blog

Threat Score
90/100

Date Published: 2026-07-02

Date Updated: 2026-07-16

...
...

Cyble Global Sensor Intelligence reports ongoing, real-world exploitation of two high-severity Ivanti Connect Secure vulnerabilities (an authentication bypass CVE-2023-46805 and a command-injection RCE CVE-2024-21887). The advisory describes how attackers enumerate unauthenticated REST endpoints, leverage path traversal and a vulnerable license API to inject commands, and have been observed exfiltrating data and establishing reverse tunnels; tens of thousands of internet-exposed instances increase the scale and urgency, with vendor mitigations and staged patches forthcoming.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.