logo

Ivanti Releases Urgent Fix for Critical Sentry RCE Vulnerability

ID: ab1682dc-b36c-5cbe-986d-1d1a45f5f93d

STIX ID: report--ab1682dc-b36c-5cbe-986d-1d1a45f5f93d

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-03-21

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Ivanti disclosed critical flaws—CVE-2023-41724 (unauthenticated RCE, CVSS 9.6) affecting Standalone Sentry and CVE-2023-46808 (authenticated remote file write → code execution, CVSS 9.9) affecting Neurons for ITSM—and released patches for affected versions; the report also highlights a separate mXSS issue in Mailspring (CVE-2023-47479) and notes that Ivanti has previously seen exploitation of its products by suspected China-linked clusters (UNC5221, UNC5325, UNC3886).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.