CVE detail
CVE-2024-21887
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
80 source links · newest first
- Storm-1175 Replaces Medusa With New StormEncryptor RansomwareSecurity Affairs
has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) catalog on August 3, 20
newssecurityaffairs.comAug 13, 2026, 8:09 AM China-based actor Storm-1175 runs fast ransomware attacks, exploiting new flaws to breach systems and quickly deploy Medusa ransomware. China-based actor Storm-1175 carries out fast, financially driven ransomware attacks by exploiting newly disclosed vulnerabilities before organizations patch them. The group targets exposed systems and quickly moves from initial access to data theft and Medusa ransomware deployment, […]
newssecurityaffairs.comApr 7, 2026, 1:20 PMWarp Panda has been using the BrickStorm, Junction, and GuestConduit malware in attacks against US organizations.
newswww.securityweek.comDec 5, 2025, 2:15 PMGetting breached by two separate and likely unconnected cyber attack groups is a nightmare scenario for any organization, but can result in an unexpected silver lining: the noisier intrusion can draw attention to a far stealthier threat that might otherwise linger undetected for months. A double whammy In a recently published report, threat researchers at Positive Technologies have detailed the findings of their investigation into two incidents at Russian companies, which they have tied to: … More →
newswww.helpnetsecurity.comDec 2, 2025, 10:51 AMA Chinese state-sponsored hacker group called RedNovember has conducted a global espionage campaign targeting critical infrastructure between June 2024 and July 2025, compromising defense contractors, government agencies, and major corporations while exploiting vulnerabilities faster than organizations could deploy security patches. The attacks included breaches of at least two US defense contractors and more than 30 […]
newswww.csoonline.comSep 29, 2025, 12:28 PMChinese threat actors deployed a custom Linux backdoor on compromised network edge devices to maintain persistent access into the networks of US legal services firms, software-as-a-service (SaaS) providers, business process outsourcers and technology companies. On average, these backdoors remained undetected for 393 days and were used as a staging point for lateral movement to VMware […]
newswww.csoonline.comSep 25, 2025, 1:05 AMGovernment intelligence and cybersecurity agencies from 13 countries have released a joint advisory detailing the techniques used by Salt Typhoon, a Chinese state-sponsored APT group that has targeted telecommunications, government, transportation, lodging and military infrastructure networks from around the world. The agencies have linked Salt Typhoon’s activities to multiple Chinese entities, including three technology companies […]
newswww.csoonline.comAug 28, 2025, 11:47 PMChina-linked APT ‘Salt Typhoon’ exploited known router flaws to maintain persistent access across telecom, government, and military networks, giving Beijing’s intelligence services global surveillance reach.
newswww.securityweek.comAug 28, 2025, 1:56 PM- NSA, NCSC, and allies detailed TTPs associated with Chinese APT actors targeting critical infrastructure OrgsSecurity Affairs
NSA and allies warn that Chinese APT actors, including Salt Typhoon, are targeting critical infrastructure worldwide. The U.S. National Security Agency (NSA), the UK’s National Cyber Security Centre (NCSC), and allies warn Chinese APT actors, linked to Salt Typhoon, are targeting global telecom, government, transport, lodging, and military sectors. “The National Security Agency (NSA) and […]
newssecurityaffairs.comAug 28, 2025, 10:47 AM - Ransomware Group Claims Attacks on UK RetailersSecurityWeek
The DragonForce ransomware group has claimed responsibility for the recent cyberattacks on UK retailers Co-op, Harrods, and M&S.
newswww.securityweek.comMay 5, 2025, 11:00 AM - The state of intrusions: Stolen credentials and perimeter exploits on the rise, as phishing wanesCSO Online
CISOs seeking insights into the latest cyberattack trends should note that cybercriminals’ initial access methods appear to be shifting, as data from both Verizon and Google-owned Mandiant underscored similar findings about intrusion techniques in separate reports. According to Mandiant, stolen credentials were responsible for more intrusions last year than phishing and were second only to […]
newswww.csoonline.comApr 29, 2025, 9:00 AM Ivanti is warning customers that a critical vulnerability that impacts its VPN appliances and other products has already been exploited in the wild by a Chinese APT group. The flaw was originally flagged by Ivanti as a denial-of-service issue, but attackers figured out how to exploit it for remote code execution. The vulnerability, now tracked […]
newswww.csoonline.comApr 4, 2025, 3:55 PMA suspected Chinese APT group has exploited CVE-2025-22457 – a buffer overflow bug that was previously thought not to be exploitable – to compromise appliances running Ivanti Connect Secure (ICS) 22.7R2.5 or earlier or Pulse Connect Secure 9.1x. The vulnerability was patched by Ivanti in ICS 22.7R2.6, released on February 11, 2025. But, apparently, the threat actor studied the patch and “uncovered through a complicated process, [that] it was possible to exploit 22.7R2.5 and earlier … More →
newswww.helpnetsecurity.comApr 3, 2025, 5:52 PMResearchers from Google’s Mandiant division believe the critical remote code execution vulnerability patched on Wednesday by software vendor Ivanti has been exploited since mid-December by a Chinese cyberespionage group. This is the same group that has exploited zero-day vulnerabilities in Ivanti Connect Secure appliances back in January 2024 and throughout the year. The latest attacks, […]
newswww.csoonline.comJan 9, 2025, 11:43 PMGoogle Cloud’s Mandiant has linked the exploitation of CVE-2025-0282, a new Ivanti VPN zero-day, to Chinese cyberspies.
newswww.securityweek.comJan 9, 2025, 10:52 AMIn 2024, hackers had a field day finding sneaky ways into systems — from convincing phishing scams that played on human curiosity to brutal software flaws that exposed gaps in tech upkeep. It was a year of clever breaches, showing just how wide the gap is between user habits and security practices. “While every year […]
newswww.csoonline.comDec 31, 2024, 6:00 AMIn 2024, nation-state cyber activity was off the charts, with Chinese, Russian, and Iranian actors leading the charge. Their campaigns weren’t just relentless — they were innovative, using a crafty mix of Tactics, Techniques, and Procedures (TTPs) to gain footholds, stay hidden, and spy-like pros. “There was definitely a continued and noted uptick in nation-state […]
newswww.csoonline.comDec 25, 2024, 6:00 AMZero-day vulnerabilities saw big growth once again in 2024. With no patch available, zero-day flaws give attackers a significant jump on cybersecurity defense teams, making them a critical weapon for attacking enterprise systems. But while all zero-days are essential for CISOs and their team to be aware of, and for vendors to remedy in a […]
newswww.csoonline.comDec 23, 2024, 9:00 AMBlack Lotus Labs estimates that more than 200,000 routers, network-attached storage servers, and IP cameras have been ensnared in the botnet.
newswww.securityweek.comSep 18, 2024, 4:00 PM- Major data breaches that have rocked organizations in 2024Help Net Security
This article provides an overview of the major data breaches we covered in 2024 so far, highlighting incidents involving Trello, AnyDesk, France Travail, Nissan, MITRE, Dropbox, BBC Pension Scheme, TeamViewer, Advance Auto Parts, and AT&T. Find out what led to the breaches and how they affected the breached organizations. The information in this recap might help your organization strengthen its cybersecurity posture. Trello January 2024 In January 2024, Trello encountered an incident in which user … More →
newswww.helpnetsecurity.comJul 16, 2024, 3:30 AM - CISA, FBI Urge Immediate Action on OS Command Injection Vulnerabilities in Network DevicesSecurityWeek
In response to recent intrusions, CISA and the FBI are urging businesses and device manufacturers to eliminate OS command injection vulnerabilities at the source.
newswww.securityweek.comJul 11, 2024, 11:24 AM CISA warned chemical facilities that its Chemical Security Assessment Tool (CSAT) environment was compromised in January. CISA warns chemical facilities that its Chemical Security Assessment Tool (CSAT) environment was breached in January. In March, the Recorded Future News first reported that the US Cybersecurity and Infrastructure Security Agency (CISA) agency was hacked in February. In response […]
newssecurityaffairs.comJun 25, 2024, 5:59 AMGovernment agencies in the US, New Zealand, and Canada have published new guidance on improving network security.
newswww.securityweek.comJun 19, 2024, 12:16 PMMITRE has shared information on how China-linked hackers abused VMware for persistence and detection evasion in the recent hack.
newswww.securityweek.comMay 23, 2024, 1:22 PMThreat actors exploit recently disclosed Ivanti Connect Secure (ICS) vulnerabilities to deploy the Mirai botnet. Researchers from Juniper Threat Labs reported that threat actors are exploiting recently disclosed Ivanti Connect Secure (ICS) vulnerabilities CVE-2023-46805 and CVE-2024-21887 to drop the payload of the Mirai botnet. In early January, the software firm reported that threat actors are exploiting two […]
newssecurityaffairs.comMay 9, 2024, 1:41 PM- MITRE breach details reveal attackers’ successes and failuresHelp Net Security
MITRE has shared a timeline of the recent breach if fell victim to and has confirmed that it began earlier than previously thought: on December 31, 2023. On that day, the attackers deployed a web shell on an external-facing Ivanti Connect Secure VPN appliance by exploiting CVE-2023–46805 and CVE-2024–21887, two zero days whose existence became publicly known in early January, when patches were still unavailable. Tools and techniques used to breach MITRE The attackers leveraged … More →
newswww.helpnetsecurity.comMay 8, 2024, 11:06 AM - MITRE attributes the recent attack to China-linked UNC5221Security Affairs
MITRE published more details on the recent security breach, including a timeline of the attack and attribution evidence. MITRE has shared more details on the recent hack, including the new malware involved in the attack and a timeline of the attacker’s activities. In April 2024, MITRE disclosed a security breach in one of its research […]
newssecurityaffairs.comMay 7, 2024, 1:40 PM MITRE has shared more details on the recent hack, including the new malware involved in the attack and a timeline of the attacker’s activities.
newswww.securityweek.comMay 7, 2024, 7:33 AMHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Hackers backdoored Cisco ASA devices via two zero-days (CVE-2024-20353, CVE-2024-20359) A state-sponsored threat actor has managed to compromise Cisco Adaptive Security Appliances (ASA) used on government networks across the globe and use two zero-day vulnerabilities (CVE-2024-20353, CVE-2024-20359) to install backdoors on them, Cisco Talos researchers have shared on Wednesday. MITRE breached by nation-state threat actor via Ivanti zero-days MITRE has … More →
newswww.helpnetsecurity.comApr 28, 2024, 8:00 AM- MITRE breached by nation-state threat actor via Ivanti zero-daysHelp Net Security
MITRE has been breached by attackers via two zero-day vulnerabilities (CVE-2023-46805, CVE-2024-21887) in Ivanti’s Connect Secure VPN devices. The attackers have also managed to move laterally and compromise the company network’s VMware infrastructure, MITRE confirmed late last week. What is known about the breach? The MITRE Corporation is an American not-for-profit organization that manages federally funded research and development centers supporting various US government agencies. “After detecting suspicious activity on [MITRE’s] Networked Experimentation, Research, and … More →
newswww.helpnetsecurity.comApr 22, 2024, 12:16 PM MITRE R&D network hacked in early January by a state-sponsored threat group that exploited an Ivanti zero-day vulnerability.
newswww.securityweek.comApr 22, 2024, 9:42 AMWe describe the characteristics of malware-initiated scanning attacks. These attacks differ from direct scanning and are increasing according to our data.
vendorunit42.paloaltonetworks.comApr 8, 2024, 10:00 PMA day after patching a batch of high-severity vulnerabilities impacting its critical services, Ivanti has made public its plans to revamp security and vulnerability management controls. In an open letter addressed to its customers and partners, Ivanti CEO, Jeff Abbott, said the revamp decision has been made in response to the frequent exploits and security […]
newswww.csoonline.comApr 5, 2024, 11:42 AMIvanti releases a carefully scripted YouTube video and an open letter from chief executive Jeff Abbott vowing to fix the entire security organization.
newswww.securityweek.comApr 4, 2024, 6:22 PMIvanti addressed four flaws impacting Connect Secure and Policy Secure Gateways that could lead to code execution and denial-of-service (DoS) condition. Ivanti has released security updates to address four security flaws impacting Connect Secure and Policy Secure Gateways that could result in code execution and denial-of-service (DoS). The list of vulnerabilities addressed by the company […]
newssecurityaffairs.comApr 4, 2024, 8:10 AMIvanti urges customers to address a critical remote code execution vulnerability impacting the Standalone Sentry solution. Ivanti addressed a critical remote code execution vulnerability, tracked as CVE-2023-41724 (CVSS score of 9.6), impacting Standalone Sentry solution. An unauthenticated attacker can exploit this vulnerability to execute arbitrary commands on the underlying operating system of the appliance within […]
newssecurityaffairs.comMar 21, 2024, 9:59 AMA financially motivated threat actor is using known vulnerabilities to target public-facing services and deliver custom malware to unpatched Windows and Linux systems. Among the exploited vulnerabilities are also two recently discovered Ivanti Connect Secure VPN flaws that are widely exploited by a variety of attackers. Magnet Goblin activity Magnet Goblin – as the threat actor has been dubbed by Check Point researchers – has been targeting unpatched edge devices and public-facing servers for years. … More →
newswww.helpnetsecurity.comMar 12, 2024, 8:55 AMA financially motivated hacker group, tracked as Magnet Goblin, has been using cracked public-facing servers through 1-day exploitations to drop custom Linux malware, according to CheckPoint. One of the group’s primary exploits included the Ivanti Connect Secure RCE bug, tracked as CVE-2024-21887, that the VPN solutions provider said had active zero-day exploitations. “Magnet Goblin quickly adopts and […]
newswww.csoonline.comMar 11, 2024, 12:21 PM- 11th March – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 11th March, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES Cybersecurity and Infrastructure Security Agency (CISA) has taken offline two systems following a breach that occurred as a result of the recent vulnerabilities exploitation in Ivanti products. The affected systems potentially include the […]
vendorresearch.checkpoint.comMar 11, 2024, 12:14 PM The financially motivated threat actor Magnet Goblin is targeting one-day vulnerabilities to deploy Nerbian malware on Linux systems.
newswww.securityweek.comMar 11, 2024, 11:50 AMThe financially motivated hacking group Magnet Goblin uses various 1-day flaws to deploy custom malware on Windows and Linux systems. A financially motivated threat actor named Magnet Goblin made the headlines for rapidly adopting and exploiting 1-day vulnerabilities, CheckPoint warned. The group focuses on internet-facing services, in at least one instance the group exploited the […]
newssecurityaffairs.comMar 11, 2024, 10:45 AM- Threat actors breached two crucial systems of the US CISASecurity Affairs
Threat actors hacked the systems of the Cybersecurity and Infrastructure Security Agency (CISA) by exploiting Ivanti flaws. The US Cybersecurity and Infrastructure Security Agency (CISA) agency was hacked in February, the Recorded Future News first reported. In response to the security breach, the agency had to shut down two crucial systems, as reported by a […]
newssecurityaffairs.comMar 9, 2024, 11:25 PM - Magnet Goblin Targets Publicly Facing Servers Using 1-Day VulnerabilitiesCheck Point Research
Key Points Introduction On January 10, 2024, Ivanti published a security advisory regarding two vulnerabilities in Ivanti Connect Secure VPN. These vulnerabilities, which were exploited in the wild, are identified as CVE-2023-46805 and CVE-2023-21887. The exploitation of these vulnerabilities was quickly adopted by a number of threat actors, resulting in a broad range of malicious activities. Check Point Research […]
vendorresearch.checkpoint.comMar 8, 2024, 12:00 PM - 4th March – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 4th March, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES UnitedHealth Group confirmed its subsidiary was attacked by the ALPHV ransomware gang. 6 terabytes of data were stolen in the attack, and Change Healthcare, a crucial intermediary between pharmacies and insurance companies, was […]
vendorresearch.checkpoint.comMar 4, 2024, 1:59 PM The Five Eyes alliance warns of threat actors exploiting known security flaws in Ivanti Connect Secure and Ivanti Policy Secure gateways. The Five Eyes intelligence alliance issued a joint cybersecurity advisory warning of threat actors exploiting known vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways. The advisory provides details about the exploitation in […]
newssecurityaffairs.comMar 1, 2024, 2:01 PMCredentials stored on Ivanti VPN appliances impacted by recent vulnerabilities are likely compromised, government agencies say.
newswww.securityweek.comMar 1, 2024, 12:30 PMChinese threat actors target Ivanti VPN appliances with new malware designed to persist system upgrades.
newswww.securityweek.comFeb 28, 2024, 12:21 PMDays after Ivanti announced patches for a new vulnerability in its Connect Secure and Policy Secure products, proof-of-concept exploit code has already been published for the flaw and security companies are reporting exploitation attempts in the wild. This follows a difficult month for Ivanti customers who had to deploy emergency mitigations and patches for three […]
newswww.csoonline.comFeb 13, 2024, 7:50 PMBackdoor deployed using recent Ivanti VPN vulnerability enables command execution, web request and system log theft.
newswww.securityweek.comFeb 13, 2024, 1:13 PM- Attackers injected novel DSLog backdoor into 670 vulnerable Ivanti devices (CVE-2024-21893)Help Net Security
Hackers are actively exploiting a vulnerability (CVE-2024-21893) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA to inject a “previously unknown and interesting backdoor” dubbed DSLog. CVE-2024-21893 patches and exploitation Ivanti disclosed CVE-2024-21893 – a server-side request forgery (SSRF) vulnerability in the SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA – in late January, when it issued patches for affected devices. At the same time, the company also fixed CVE-2024-21888, … More →
newswww.helpnetsecurity.comFeb 13, 2024, 10:58 AM - Ivanti warns of a new auth bypass flaw in its Connect Secure, Policy Secure, and ZTA gateway devicesSecurity Affairs
Ivanti warns customers of a new authentication bypass vulnerability in its Connect Secure, Policy Secure, and ZTA gateway devices. Ivanti has warned customers of a new high-severity security vulnerability, tracked as CVE-2024-22024 (CVSS score 8.3), in its Connect Secure, Policy Secure, and ZTA gateway devices that could allow attackers to bypass authentication. The vulnerability was […]
newssecurityaffairs.comFeb 9, 2024, 8:17 AM CVE-2024-21893, a server-side request forgery (SSRF) vulnerability affecting Ivanti Connect Secure VPN gateways and Policy Secure (a network access control solution), is being exploited by attackers. About CVE-2024-21893 CVE-2024-21893 allows a attackers to bypass authentication requirements and access certain restricted resources on vulnerable solutions. It affects the SAML component of: Ivanti Connect Secure (9.x, 22.x) Ivanti Policy Secure (9.x, 22.x) Ivanti Neurons for ZTA (SaaS-delivered zero trust network access solution) Its existence, along with that … More →
newswww.helpnetsecurity.comFeb 7, 2024, 10:10 AMIn January, Ivanti alerted customers that hackers were exploiting two zero-day vulnerabilities in its Ivanti Connect Secure and Ivanti Policy Secure. This week the company revealed that two other vulnerabilities were discovered in the meantime, with one already being exploited in targeted attacks. Even though patches are now available for all four vulnerabilities, the US […]
newswww.csoonline.comFeb 2, 2024, 8:33 PMCISA is ordering federal agencies to disconnect Ivanti Connect Secure and Ivanti Policy Secure products within 48 hours. For the first time since its establishment, CISA is ordering federal agencies to disconnect all instances of Ivanti Connect Secure and Ivanti Policy Secure products within 48 hours. The CISA’s emergency directive orders to disconnect all instances […]
newssecurityaffairs.comFeb 1, 2024, 7:46 PMIn an unprecedented move, CISA is demanding that federal agencies disconnect all instances of Ivanti Connect Secure and Ivanti Policy Secure products within 48 hours.
newswww.securityweek.comFeb 1, 2024, 4:43 PM- Multiple malware used in attacks exploiting Ivanti VPN flawsSecurity Affairs
Mandiant spotted new malware used by a China-linked threat actor UNC5221 targeting Ivanti Connect Secure VPN and Policy Secure devices. Mandiant researchers discovered new malware employed by a China-linked APT group known as UNC5221 and other threat groups targeting Ivanti Connect Secure VPN and Policy Secure devices. The attackers were observed exploiting CVE-2023-46805 and CVE-2024-21887 […]
newssecurityaffairs.comFeb 1, 2024, 10:53 AM Ivanti documents a brand-new zero-day and belatedly ships patches; Mandiant is reporting “broad exploitation activity.”
newswww.securityweek.comJan 31, 2024, 5:07 PM- Ivanti warns of a new actively exploited zero-daySecurity Affairs
Ivanti warns of two new vulnerabilities in its Connect Secure and Policy Secure products, one of which is actively exploited in the wild. Ivanti is warning of two new high-severity vulnerabilities in its Connect Secure and Policy Secure solutions respectively tracked as CVE-2024-21888 (CVSS score: 8.8) and CVE-2024-21893 (CVSS score: 8.2). The software company also warned that […]
newssecurityaffairs.comJan 31, 2024, 2:37 PM Threat actors are exploiting recently disclosed zero-day flaws in Ivanti Connect Secure (ICS) VPN devices to deliver KrustyLoader. In early January 2024, software firm Ivanti reported that threat actors were exploiting two zero-day vulnerabilities (CVE-2023-46805, CVE-2024-21887) in Connect Secure (ICS) and Policy Secure to remotely execute arbitrary commands on targeted gateways. Researchers from cybersecurity firm Synacktiv published […]
newssecurityaffairs.comJan 31, 2024, 11:45 AMIvanti is struggling to hit its own timeline for the delivery of patches for critical — and already exploited — flaws in its flagship VPN appliances.
newswww.securityweek.comJan 29, 2024, 7:16 PMTwo recent Ivanti CVEs are being actively exploited by suspected nation-state threat actors.
exploithorizon3.aiJan 22, 2024, 6:28 PMThe US government’s cybersecurity agency CISA ramps up the pressure on organizations to mitigate two exploited Ivanti VPN vulnerabilities.
newswww.securityweek.comJan 19, 2024, 8:52 PM- Ivanti EPMM and MobileIron Core vulnerability is actively exploited, CISA confirms (CVE-2023-35082)Help Net Security
A previously patched critical vulnerability (CVE-2023-35082) affecting Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core is being actively exploited, the Cybersecurity and Infrastructure Security Agency (CISA) has confirmed by adding the vulnerability to its Known Exploited Vulnerabilities Catalog (KEV). It is not known whether the vulnerability is being exploited by ransomware groups, and CISA does not publish specific information about attacks in which the vulnerabilities in the KEV catalog are exploited. But it does seem … More →
newswww.helpnetsecurity.comJan 19, 2024, 5:32 PM The number of Ivanti VPN appliances compromised through exploitation of recent flaws increases and another vulnerability is added to exploited list.
newswww.securityweek.comJan 19, 2024, 11:01 AMMultiple CVEs affecting Ivanti products: CVE-2023-46805, CVE-2024-21887, CVE-2024-21888, CVE-2024-21893 and CVE-2023-46805 are detailed in this threat brief.
vendorunit42.paloaltonetworks.comJan 16, 2024, 11:30 PM- 1,700 Ivanti VPN devices compromised. Are yours among them?Help Net Security
Over 1,700 Ivanti Connect Secure VPN devices worldwide have been compromised by attackers exploiting two zero-days with no patches currently available. “Additional threat actors beyond UTA0178 appear to now have access to the exploit and are actively trying to exploit devices,” Volexity researchers claim. Initial findings Both Volexity and Ivanti revealed on January 10 that unknown attackers have been leveraging exploits for CVE-2023-46805 (authentication bypass) and CVE-2024-21887 (command injection vulnerability) to breach organizations and ultimately … More →
newswww.helpnetsecurity.comJan 16, 2024, 3:07 PM Experts warn that recently disclosed Ivanti Connect Secure VPN and Policy Secure vulnerabilities are massively exploited in the wild. Last week, software firm Ivanti reported that threat actors are exploiting two zero-day vulnerabilities (CVE-2023-46805, CVE-2024-21887) in Connect Secure (ICS) and Policy Secure to remotely execute arbitrary commands on targeted gateways. The flaw CVE-2023-46805 (CVSS score […]
newssecurityaffairs.comJan 16, 2024, 10:40 AMThe recently disclosed Ivanti VPN zero-days have been exploited to hack at least 1,700 devices, including government, telecoms, defense, and tech.
newswww.securityweek.comJan 16, 2024, 9:59 AM- 15th January – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 15th January, please download our Threat_Intelligence Bulletin. TOP ATTACKS AND BREACHES The ransomware-as-a-service group Medusa has breached Water for People nonprofit organization, which aims to improve access to clean water in different countries including Guatemala, Honduras, Mozambique and India. The cybercriminals are asking for […]
vendorresearch.checkpoint.comJan 15, 2024, 11:52 AM - Week in review: GitLab account takeover flaw, attackers exploiting Ivanti Connect Secure zero-daysHelp Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Social engineer reveals effective tricks for real-world intrusions In this Help Net Security interview, Jayson E. Street, Chief Adversarial Officer at Secure Yeti, discusses intriguing aspects of social engineering and unconventional methods for gathering target information. Understanding zero-trust design philosophy and principles In this Help Net Security interview, Phil Vachon, Head of Infrastructure in the Office of the CTO at … More →
newswww.helpnetsecurity.comJan 14, 2024, 7:24 AM A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Akira ransomware targets Finnish organizations GitLab fixed a critical zero-click account hijacking flaw Juniper Networks fixed […]
newssecurityaffairs.comJan 13, 2024, 11:42 PMNo excerpt available.
Mitigationwww.cisa.govJan 12, 2024, 5:15 PMNo excerpt available.
Exploitforums.ivanti.comJan 12, 2024, 5:15 PM- http://packetstormsecurity.com/files/176668/Ivanti-Connect-Secure-Unauthenticated-Remote-Code-Execution.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comJan 12, 2024, 5:15 PM Ivanti zero-day vulnerabilities dubbed ConnectAround could impact thousands of systems and Chinese cyberspies are preparing for patch release.
newswww.securityweek.comJan 12, 2024, 10:43 AM- CISA adds Ivanti and Microsoft SharePoint bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Connect Secure and Microsoft SharePoint bugs to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Ivanti Connect Secure and Policy Secure flaws, tracked as CVE-2024-21887 and CVE-2023-46805, and Microsoft SharePoint Server flaw CVE-2023-29357 to its Known Exploited Vulnerabilities (KEV) catalog. Software firm […]
newssecurityaffairs.comJan 11, 2024, 3:33 PM - Two zero-day bugs in Ivanti Connect Secure actively exploitedSecurity Affairs
Ivanti revealed that two threat actors are exploiting two zero-day vulnerabilities in its Connect Secure (ICS) and Policy Secure. Software firm Ivanti reported that threat actors are exploiting two zero-day vulnerabilities (CVE-2023-46805, CVE-2024-21887) in Connect Secure (ICS) and Policy Secure to remotely execute arbitrary commands on targeted gateways. The flaw CVE-2023-46805 (CVSS score 8.2) is […]
newssecurityaffairs.comJan 11, 2024, 3:03 PM Two critically severe zero-day vulnerabilities in devices running Ivanti VPN services are being actively exploited by Chinese nation-state actors for unauthenticated remote code execution, according to Volexity research. Tracked as CVE-2023-46805 and CVE-2024-21887, the vulnerabilities, with CVSS scores 8.2 and 9.1 respectively, have been discovered in Ivanti Connect Secure (formerly known as Pulse Connect Secure), […]
newswww.csoonline.comJan 11, 2024, 1:04 PM- Ivanti Connect Secure zero-days exploited by attackers (CVE-2023-46805, CVE-2024-21887)Help Net Security
Two zero-day vulnerabilities (CVE-2023-46805, CVE-2024-21887) in Ivanti Connect Secure VPN devices are under active exploitation by unknown attackers, Volexity researchers have discovered. Patches for these flaws are currently unavailable, but the risk of exploitation can be mitigated by importing mitigation.release.20240107.1.xml file via Ivanti’s download portal. About the vulnerabilities (CVE-2023-46805, CVE-2024-21887) The two security flaws affect all supported versions (v9.x and 22.x) of Ivanti Connect Secure (ICS) – formerly known as Pulse Connect Secure – and … More →
newswww.helpnetsecurity.comJan 11, 2024, 11:35 AM Ivanti confirms active zero-day exploits, ships pre-patch mitigations, but says comprehensive fixes won’t be available until January 22.
newswww.securityweek.comJan 10, 2024, 9:22 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-11634CVSS 9.1 · Critical
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to…
- CVE-2021-22938CVSS 7.2 · High
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator…
- CVE-2021-22935CVSS 7.2 · High
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.
- CVE-2021-22899CVSS 8.8 · High
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profi…
- CVE-2025-8712CVSS 5.4 · Medium
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secur…
- CVE-2025-8711CVSS 5.4 · Medium
CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22…