logo

Ivanti patches two zero-days under attack, but finds another

ID: 560d7866-28d4-5bbc-a994-613d036346f1

STIX ID: report--560d7866-28d4-5bbc-a994-613d036346f1

Feed Name: TechCrunch Security News

Threat Score
90/100

Date Published: 2024-01-31

Date Updated: 2026-04-23

Author: Carly Page

...
...

Ivanti has disclosed multiple critical vulnerabilities in its Connect Secure VPN product, including recently discovered zero-days that allow privilege escalation and server-side authentication bypass. Security firms (Volexity, Mandiant) and government bodies (BSI, CISA) report active, targeted exploitation—attributed in part to Chinese state-backed actors—with thousands of appliances compromised and mitigations being bypassed; Ivanti has released staggered patches and recommends factory resets prior to patching to remove persistent access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.