logo

US gives federal agencies 48 hours to disconnect flawed Ivanti VPN tech

ID: 4d4b1b23-54d1-5abd-b459-5acbd1f2272c

STIX ID: report--4d4b1b23-54d1-5abd-b459-5acbd1f2272c

Feed Name: TechCrunch Security News

Threat Score
90/100

Date Published: 2024-02-01

Date Updated: 2026-04-23

Author: Carly Page

...
...

CISA has ordered U.S. federal agencies to immediately disconnect Ivanti Connect Secure and Ivanti Policy Secure VPN appliances after multiple zero-day vulnerabilities (including CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893) were found to be actively exploited—attributed to Chinese state-backed actors—with at least 2,200 devices reported compromised; Ivanti released patches and advised factory resets and fresh installs to remove potential persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.