Attackers globally exploited CVE-2023-46805 and CVE-2024-21887 in Ivanti Connect Secure and Ivanti Policy Secure gateways, chaining the flaws to achieve unauthenticated remote code execution with administrator privileges. The affected products included supported Connect Secure 9.x and 22.x releases and supported Policy Secure versions; because the appliances are commonly internet-facing, compromise could enable data theft, lateral movement, and ransomware deployment.
Ivanti issued updates for specified Connect Secure and ZTA versions, while CISA warned that the vendor's initial mitigations and detection guidance might not fully address the threat. Ivanti also disclosed CVE-2024-21888 and CVE-2024-21893, for which proof-of-concept code became public; organizations were urged to apply updates immediately, factory-reset affected appliances where recommended, and use mitigations only until patches could be installed.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
Proof-of-concept exploit code for the additional Ivanti vulnerability CVE-2024-21893 was publicly shared.
Researchers published an exploit for CVE-2023-46805 that could potentially also be used to exploit CVE-2024-21887 in Ivanti gateways.
Ivanti disclosed CVE-2024-22024, a high-severity authentication-bypass vulnerability in the SAML component of Connect Secure, Policy Secure, and ZTA gateways. The flaw permits unauthenticated access to certain restricted resources.
Researchers identified a prefix-based authentication exception for the TOTP backup-code path that could be combined with path traversal to access protected Ivanti REST endpoints, including on older 9.1R11.4 systems. They chained the bypass with command injection in the license-keys-status API to obtain a root-level reverse shell on an Ivanti Connect Secure appliance.
Ivanti disclosed two additional vulnerabilities, CVE-2024-21888 and CVE-2024-21893, and provided mitigations for environments where relevant patches had not yet been installed.
CISA cautioned that Ivanti's earlier mitigation measures and detection methods might not adequately address compromises of vulnerable appliances.
Ivanti released security updates for specified Connect Secure versions—9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, and 22.5R1.1—and ZTA 22.6R1.3.
Ivanti Connect Secure and Policy Secure gateways were reported under active exploitation using CVE-2023-46805 and CVE-2024-21887 together, allowing unauthenticated remote code execution with administrator privileges. Volexity reported that exploitation was occurring at large scale.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
slcyber.io
Open sourcelabs.watchtowr.com
Open sourcewiz.io
Open sourcencsc.nl
Open sourcevolexity.com
Open sourcethreats.wiz.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.