Alert: Ivanti Discloses 2 New Zero-Day Flaws, One Under Active Exploitation
ID: 2a90248c-dd8e-580a-b04c-d077dba1cdd4
STIX ID: report--2a90248c-dd8e-580a-b04c-d077dba1cdd4
Feed Name: The Hacker News
Ivanti disclosed two high-severity vulnerabilities in its Connect Secure and Policy Secure products—CVE-2024-21888 (privilege escalation, CVSS 8.8) and CVE-2024-21893 (SSRF, CVSS 8.2)—and released fixes and temporary mitigations; the vendor said CVE-21893 appears to be targeted in the wild with a limited number of customers impacted and warned of likely increased exploitation once public, while CISA has also warned that related Ivanti flaws have been broadly exploited to deploy backdoors, miners, and loaders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
