logo

Alert: Ivanti Discloses 2 New Zero-Day Flaws, One Under Active Exploitation

ID: 2a90248c-dd8e-580a-b04c-d077dba1cdd4

STIX ID: report--2a90248c-dd8e-580a-b04c-d077dba1cdd4

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-01-31

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Ivanti disclosed two high-severity vulnerabilities in its Connect Secure and Policy Secure products—CVE-2024-21888 (privilege escalation, CVSS 8.8) and CVE-2024-21893 (SSRF, CVSS 8.2)—and released fixes and temporary mitigations; the vendor said CVE-21893 appears to be targeted in the wild with a limited number of customers impacted and warned of likely increased exploitation once public, while CISA has also warned that related Ivanti flaws have been broadly exploited to deploy backdoors, miners, and loaders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.