Attackers exploited two zero-day vulnerabilities in Ivanti Connect Secure VPN appliances, chaining authentication bypass CVE-2023-46805 with command injection CVE-2024-21887 to execute arbitrary commands without authentication. Volexity reported active exploitation, while Ivanti confirmed limited customer exploitation. The vendor’s expanded advisory covers five vulnerabilities affecting Connect Secure, Policy Secure and, for certain flaws and deployment conditions, Neurons for ZTA gateways. Ivanti reported that fewer than 20 customers were affected before public disclosure by exploitation involving the original pair and CVE-2024-21893.
Patches are available, but Ivanti also recommends factory resetting hardware appliances or rebuilding virtual appliances to address potential attacker persistence. Defenders should use Ivanti’s External Integrity Checker Tool alongside continuous security monitoring: attackers have attempted to manipulate the internal integrity checker, and clean integrity-check results do not rule out earlier compromise. Remediation should therefore address both vulnerable software and possible persistent access rather than treating patch installation alone as evidence that an appliance is safe.

See which actors are running it and whether you're in range.
11 events from the most recent confirmed update back to the earliest known activity.
Ivanti disclosed CVE-2023-46805 and CVE-2024-21887 in Connect Secure and Policy Secure. Chaining the vulnerabilities allows an unauthenticated remote attacker to execute arbitrary system commands through malicious requests.
Ivanti observed threat actors attempting to manipulate the internal Integrity Checker Tool and recommended that all customers run the external checker. It warned that a clean result captures only the appliance's current state and cannot exclude earlier compromise.
Ivanti's advisory also disclosed privilege escalation CVE-2024-21888, SAML SSRF CVE-2024-21893 and SAML XXE CVE-2024-22024. Ivanti reported limited customer exploitation of CVE-2024-21893, but no evidence of customer impact from the other two flaws at disclosure.
Ivanti announced patch availability for version 22.2R3 of Connect Secure and Policy Secure.
Ivanti released appliance patches and an External Integrity Checker update that should be used only after installing those patches. The company warned that using the updated checker with earlier Connect Secure versions would generate substantial false positives.
Ivanti released an enhanced External Integrity Checker Tool that provides customers with a decrypted appliance snapshot to support investigation.
Ivanti listed patched releases for six additional Connect Secure versions and three Policy Secure versions. Together with the February 8 releases, these patches replaced those released on January 31 and February 1.
Ivanti's update listed patched releases across seven Connect Secure versions, three Policy Secure versions and three ZTA gateway versions. Customers who had already successfully factory reset and patched their appliances did not need another factory reset.
Ivanti released additional patches for affected appliances. Like the January 31 patches, these were subsequently replaced by the February 8 and February 14 releases.
Ivanti released patches for affected appliances. These patches were subsequently replaced by the February 8 and February 14 releases.
Volexity identified and reported vulnerabilities in Ivanti Connect Secure. Ivanti confirmed that attackers had exploited CVE-2023-46805 and CVE-2024-21887 against a limited number of customers before public disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
volexity.com
Open sourceforums.ivanti.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.