logo

Critical Vulnerabilities in Ivanti Exploited in-the-Wild: everything you need to know

ID: a6aeadda-0a74-5d2e-8de7-3c1b6382efc6

STIX ID: report--a6aeadda-0a74-5d2e-8de7-3c1b6382efc6

Feed Name: Wiz Blog

Threat Score
90/100

Date Published: 2024-02-06

Date Updated: 2026-05-01

...
...

Ivanti disclosed multiple high-severity vulnerabilities (CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893 and CVE-2024-22024) affecting Ivanti Connect Secure, Ivanti Policy Secure and ZTA gateways that allow authentication bypass, SSRF, command injection, privilege escalation and potential remote code execution; several were exploited in the wild (reported as 0-days) by a suspected China-aligned espionage group (UNC5221/UTA0178) beginning in December 2023. Ivanti has released patches and workarounds, CISA mandated disconnection and remediation for federal agencies, and the report urges urgent patching, threat hunting and scanning for related IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.