CVE-2024-21887Active Exploitation(ivanti / connect_secure)

HIGHCVSS 9.1 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch ivanti connect_secure systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

7.8/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-01-22. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-77

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect_secure
  • policy_secure

Threat summary

  • Active exploitation appears in 9 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 14 mentions across 13 observed days

What's happening

  • Active exploitation reported across 9 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 10d ago at 2 mentions (2026-05-04); latest day: 1
  • 14 total mentions across 13 days

Affected systems

Vendors
Products
connect_securepolicy_secure

8 versions affected across 2 products

Deep dive

Activity timeline14 mentions / 13d
01122Mentions · 2026-03-09: 1Mentions · 2026-04-25: 1Mentions · 2026-05-04: 2Mentions · 2026-05-19: 1Mentions · 2026-06-12: 1Mentions · 2026-06-18: 1Mentions · 2026-07-15: 1Mentions · 2026-07-16: 1Mentions · 2026-07-24: 1Mentions · 2026-09-25: 1Mentions · 2026-09-30: 1Mentions · 2026-10-05: 1Mentions · 2026-10-06: 1PoC Mentioned / Linked · 2026-06-18: 1Exploit Tool / Code · 2026-06-18: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-05-04: 1Active Exploitation · 2026-05-19: 1Active Exploitation · 2026-06-18: 1Active Exploitation · 2026-07-15: 1Active Exploitation · 2026-07-16: 1Active Exploitation · 2026-07-24: 1Active Exploitation · 2026-09-25: 1Active Exploitation · 2026-09-30: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-06-12: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-07-15: 1Patch / Workaround · 2026-07-16: 1Patch / Workaround · 2026-07-24: 1Technical Details · 2026-03-09: 1Technical Details · 2026-04-25: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-19: 1Technical Details · 2026-06-12: 1Technical Details · 2026-06-18: 1Technical Details · 2026-07-16: 1Technical Details · 2026-07-24: 103-0904-2505-0405-1906-1206-1807-1507-1607-2409-2509-3010-0510-06
Signal classification4 categories
Active Exploitation
975.0%
General
18.3%
Disclosure
18.3%
Patch
18.3%
Referenced assets34 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-091
Active Exploitation1
2026-04-251
General1
2026-05-042
Active Exploitation1Disclosure1
2026-05-191
Active Exploitation1
2026-06-121
Patch1
2026-06-181
Active Exploitation1
2026-07-151
Active Exploitation1
2026-07-161
Active Exploitation1
2026-07-241
Active Exploitation1
2026-09-251
Active Exploitation1
2026-09-301
Active Exploitation1
Full discourse14 posts
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Operation Escaneo exposed: a coordinated campaign hit Mexican 🇲🇽 government, financial, and critical infrastructure targets via chained Fortinet and Ivanti exploits, leaving 1.3M+ records and Active Directory maps stolen. Key findings: - Initial access via CVE-2022-42475, CVE-2024-21762 (FortiOS SSL-VPN) and CVE-2023-46805, CVE-2024-21887, CVE-2025-0282 (Ivanti Connect Secure), with PoC code tuned to avoid crashing targets. Lateral movement extended to GhostCat, EternalBlue, Zerologon, and Log4Shell. - Custom recon engine "Kimera" auto-scanned and triaged victims, feeding directly into the exploitation stage. Neo-reGeorg webshells landed first, then Chisel reverse tunnels (3,708 sessions over 13 days) and a GRE tunnel through a compromised Cisco router moved traffic below host-based detection. - Exfil included 1.3M personal records, a 407MB Active Directory map, live-streamed SSL private keys, SAP service-account hashes, and browser-stored passwords. Attackers reached SAP and Oracle for command execution inside victim networks. - The group was exposed by an open staging directory, a self-inflicted OPSEC failure that let CloudSEK reconstruct the full toolkit. Hunt for GRE tunnels terminating at external IPs, Chisel TCP-over-HTTP sessions, and unexpected process execution under SAP or Oracle service accounts. Patch the listed Fortinet and Ivanti CVEs first; those are confirmed active entry points here. #DFIR_Radar

    Post summary

    The text reports a successful, ongoing campaign exploiting multiple Fortinet and Ivanti CVEs with PoC code, using known exploits and custom tools, and urges immediate patching.

    10021476
    1.8K followersView on X
  • DFIR Radar@DFIR_Radar

    Cling botnet exploits CVE-2021-35394 (CVSS 9.8) in Realtek Jungle SDK, abusing public STUN infrastructure to disguise C2 traffic as legitimate NAT-traversal activity across routers, DVRs, and embedded Linux devices. Key details: - Exploitation of CVE-2021-35394 spiked around September 5, 2026, delivering Cling (also tracked as ClingSTUN by Fortinet). The botnet embeds hard-coded exploits for seven CVEs used in self-propagation: CVE-2014-8361 (Realtek), CVE-2016-20016 (MVPower), CVE-2023-26801 (LB-LINK), CVE-2023-41011 (China 🇨🇳 Mobile/FiberHome), CVE-2024-3721 (TBK DVR), CVE-2025-34037 (Linksys), and CVE-2026-87827 (KGUARD DVR). Initial access spans a much wider set including D-Link, Tenda, Ivanti Connect Secure (CVE-2023-46805, CVE-2024-21887), TP-Link CVE-2023-1389, AVTECH CVE-2024-7029, and others. - The C2 mechanism is the standout: Cling sends STUN Binding Requests to 13 hard-coded servers every five seconds, using an all-zero transaction ID (a deliberate protocol deviation). It then sends custom UDP registration datagrams containing mapped ports and infection-source tags like realtek.selfrep or selfrep.router. Operator commands arrive embedded in the STUN transaction ID field. The controlled server 145.249.115[.]184 returns all-zero transaction IDs rather than echoing the request, the tell that it is operator-controlled. More striking: observed command packets originate from 74.125.250[.]129, an IP resolving to stun.l[.]google[.]com, making malicious replies visually indistinguishable from Google STUN responses. - Persistence is layered: the binary copies itself to /root/.cling and /usr/local/bin/.cling, then appends both paths to /etc/inittab, /etc/init.d/rcS, and /etc/rc.d/rc.boot for SysV and BusyBox init survival. A secondary persistence method replaces the legitimate wget binary with the malware, relocating the original, so any legitimate process invoking wget executes the bot instead. Single-instance enforcement uses SO_REUSEADDR on port 33957. - Once established, Cling supports recursive scanning and worm-like spread, TCP tunnel spawn/stop, proxy launch/stop, and timed DoS floods. Observed flood targets include 112.151.157[.]222:8080, 192.170.240[.]137:53, and Minecraft servers at 23.81.40[.]193:25565 and 147.185.221[.]129:25565. Payloads are fetched via shell script downloaders for ARM, MIPS R3000, PowerPC, Intel 80386, and AMD X86-64, maximizing the range of vulnerable embedded hardware. Network defenders: hunt outbound UDP to port 3478 with zero-byte transaction IDs and flag UDP datagrams to public STUN servers that do not conform to RFC 5389 (non-random transaction IDs, oversized or non-standard payloads). On the host side, check for /root/.cling, /usr/local/bin/.cling, and modifications to /etc/inittab or rcS. Validate the wget binary hash against a known-good baseline: a replaced wget is a clean persistence indicator with no legitimate use case. Port 33957 bound with SO_REUSEADDR on a router or DVR is a direct Cling presence signal. Full IOC list is in the Nozomi Networks report. #DFIR_Radar

    10000204
    2.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    ShinyHunters exploited CVE-2024-21887 to breach FBI systems and extract 2-3 terabytes of sensitive personnel data. The group pivoted through SSO accounts and cloud platforms to compromise 140+ organizations for $70M+ in extortion payments. Runtime segmentation could help limit such lateral movement across cloud environments. #ZeroDay #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/fbi-tells-shinyhunters-members-turn-themselves-in-after-recent-arrest

    Post summary

    The text reports that threat actor ShinyHunters actively exploited CVE-2024-21887 to breach FBI systems and exfiltrate data across multiple organizations, prioritizing the attack impact narrative over technical details or remediation guidance.

    0001076
    2.0K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Salt Typhoon used CVE-2023-20198 and CVE-2024-21887 for initial access, then implanted GRE tunnels on backbone routers for persistent exfiltration. Audit every tunnel, mirror session, and AAA config against an approved baseline. #DFIR_Radar https://t.co/KJglavMdqm

    Post summary

    The tweet reports that Salt Typhoon leveraged CVE-2023-20198 and CVE-2024-21887 for initial access and deployed GRE tunnels on routers for persistent exfiltration, highlighting active threat actor usage of the vulnerabilities.

    10000164
    2.0K followersView on X
  • ro0TCr4k@ro0TCr4k
    Active Exploitation

    Ivanti VPN zero-day (CVE-2024-21887) actively exploited in the wild. Mass credential harvesting and lateral movement detected. Patch immediately. We're tracking affiliated threat actor playbooks.

    Post summary

    The post reports that CVE-2024-21887 is being actively exploited in the wild, demanding immediate patching to prevent credential harvesting and lateral movement.

    00010215
    352 followersView on X
  • ZeroDay Post@ZeroDayPost
    Active Exploitation

    Right now, APT groups are actively weaponizing Ivanti CVE-2024-21887, bypassing authentication on exposed Connect Secure VPNs. They're dropping custom backdoors and pivoting into internal networks. Systems without recent fixes are compromised. #CyberSecurity

    Post summary

    The post reports that APT groups are actively exploiting CVE‑2024‑21887 by bypassing authentication in Ivanti Connect Secure VPNs and deploying custom backdoors to pivot into internal networks.

    00010107
    5 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-21887: Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to…

    Post summary

    Ivanti Connect Secure and Policy Secure contain a command injection flaw in their web components, enabling authenticated administrators to send crafted requests that could lead to unauthorized command execution.

    1000053
    152 followersView on X
  • RST Cloud@rst_cloud

    #threatreport #LowCompleteness ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure | 05-10-2026 Source: https://www.fortinet.com/blog/threat-research/clingstun-linux-backdoor-abuses-public-stun-infrastructure Key details below ↓ 💀Threats: Clingstun, 🎯Victims: Internet facing devices, Iot devices, Linux devices, Routers 🔓CVEs: CVE-2026-87827 \[[Vulners](https://vulners.com/cve/CVE-2026-87827)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True CVE-2024-10915 \[[Vulners](https://vulners.com/cve/CVE-2024-10915)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - dlink dns-320_firmware (*) CVE-2024-3721 \[[Vulners](https://vulners.com/cve/CVE-2024-3721)] - CVSS V3.1: *6.3*, - Vulners: Exploitation: True CVE-2019-7256 \[[Vulners](https://vulners.com/cve/CVE-2019-7256)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - nortekcontrol linear_emerge_essential_firmware (le1.00-06) CVE-2016-20016 \[[Vulners](https://vulners.com/cve/CVE-2016-20016)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - mvpower tv-7104he_firmware (1.8.4_115215b9) CVE-2024-32292 \[[Vulners](https://vulners.com/cve/CVE-2024-32292)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: Unknown Soft: - tenda w30e_firmware (1.0.1.25\(633\)) CVE-2021-35394 \[[Vulners](https://vulners.com/cve/CVE-2021-35394)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - realtek rtl819x_jungle_software_development_kit (le3.4.14b) CVE-2024-32281 \[[Vulners](https://vulners.com/cve/CVE-2024-32281)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: Unknown Soft: - tenda ac7_firmware (15.03.06.44) CVE-2024-32314 \[[Vulners](https://vulners.com/cve/CVE-2024-32314)] - CVSS V3.1: *3.8*, - Vulners: Exploitation: Unknown Soft: - tenda ac500_firmware (2.0.1.9\(1307\)) CVE-2025-67038 \[[Vulners](https://vulners.com/cve/CVE-2025-67038)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - lantronix eds5008_firmware (<2.2.0.0r1) CVE-2024-46048 \[[Vulners](https://vulners.com/cve/CVE-2024-46048)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - tenda fh451_firmware (1.0.0.9) CVE-2023-26801 \[[Vulners](https://vulners.com/cve/CVE-2023-26801)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - lb-link bl-lte300_firmware (1.0.8) CVE-2022-37055 \[[Vulners](https://vulners.com/cve/CVE-2022-37055)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink go-rt-ac750_firmware (2.00b02) CVE-2023-41011 \[[Vulners](https://vulners.com/cve/CVE-2023-41011)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - chinamobile intelligent_home_gateway_firmware (hg6543c4) CVE-2022-35555 \[[Vulners](https://vulners.com/cve/CVE-2022-35555)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - tenda w6_firmware (1.0.0.9\(4122\)) CVE-2024-10914 \[[Vulners](https://vulners.com/cve/CVE-2024-10914)] - CVSS V3.1: *8.1*, - Vulners: Exploitation: True Soft: - dlink dns-320_firmware (*) CVE-2023-1389 \[[Vulners](https://vulners.com/cve/CVE-2023-1389)] - CVSS V3.1: *8.8*, - Vulners: Exploitation: True Soft: - tp-link archer_ax21_firmware (<1.1.4) CVE-2024-7029 \[[Vulners](https://vulners.com/cve/CVE-2024-7029)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - avtech avm1203_firmware (lefullimg-1023-1007-1011-1009) CVE-2025-34035 \[[Vulners](https://vulners.com/cve/CVE-2025-34035)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - engeniustech esr300_firmware (1.1.0.28, 1.3.1.42, 1.4.0, 1.4.1.28, 1.4.2) CVE-2024-23624 \[[Vulners](https://vulners.com/cve/CVE-2024-23624)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - dlink dap-1650_firmware (-) CVE-2022-36553 \[[Vulners](https://vulners.com/cve/CVE-2022-36553)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - hytec hwl-2511-ss_firmware (le1.05) CVE-2019-17621 \[[Vulners](https://vulners.com/cve/CVE-2019-17621)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink dir-859_firmware (le1.05b03, 1.06b01) CVE-2026-36356 \[[Vulners](https://vulners.com/cve/CVE-2026-36356)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True CVE-2025-34037 \[[Vulners](https://vulners.com/cve/CVE-2025-34037)] - CVSS V3.1: *10.0*, - Vulners: Exploitation: True CVE-2024-23625 \[[Vulners](https://vulners.com/cve/CVE-2024-23625)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - dlink dap-1650_firmware (-) CVE-2024-35340 \[[Vulners](https://vulners.com/cve/CVE-2024-35340)] - CVSS V3.1: *8.6*, - Vulners: Exploitation: Unknown Soft: - tenda fh1206_firmware (1.2.0.8\(8155\)) CVE-2023-46805 \[[Vulners](https://vulners.com/cve/CVE-2023-46805)] - CVSS V3.1: *8.2*, - Vulners: Exploitation: True Soft: - ivanti connect_secure (9.0, 9.1, 22.1, 22.2, 22.3) - ivanti policy_secure (9.0, 9.1, 22.1, 22.2, 22.3) CVE-2024-21887 \[[Vulners](https://vulners.com/cve/CVE-2024-21887)] - CVSS V3.1: *9.1*, - Vulners: Exploitation: True Soft: - ivanti connect_secure (9.0, 9.1, 22.1, 22.2, 22.3) - ivanti policy_secure (9.0, 9.1, 22.1, 22.2, 22.3) CVE-2022-26289 \[[Vulners](https://vulners.com/cve/CVE-2022-26289)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: Unknown Soft: - tenda m3_firmware (1.0.0.12\(4856\)) CVE-2014-8361 \[[Vulners](https://vulners.com/cve/CVE-2014-8361)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - dlink dir-905l_firmware (le2.05b01) CVE-2021-36380 \[[Vulners](https://vulners.com/cve/CVE-2021-36380)] - CVSS V3.1: *9.8*, - Vulners: Exploitation: True Soft: - sunhillo sureline (<8.7.0.1.1) 📚TTPs: ⚔️Tactics: 3 🛠️Technics: 0 🤖LLM extracted TTPs:` T1036, T1037, T1057, T1071, T1090, T1105, T1190, T1547, T1564 🧨IOCs: - IP: 3 - File: 5 - Hash: 21 💽Software: Linux, WebRTC, Ivanti, Tenda, LB-LINK 💻Platforms: mips, arm, intel #threatreport: ClingSTUN is a Linux backdoor that exploits Internet-facing, unpatched devices and converts them into remotely controlled proxy nodes. Initial delivery was observed through exploitation of CVE-2022-36553, a command-injection vulnerability in Hytec Inter HWL-2511-SS routers. Subsequent campaigns used command injection in the EnGenius IoT cloud service (CVE-2025-34035), D-Link UPnP (CVE-2024-23625), Linear and other IoT devices, Realtek devices affected by CVE-2021-35394, TP-Link Archer AX21 devices affected by CVE-2023-1389, AVTECH AVM1203 devices affected by CVE-2024-7029, and D-Link devices affected by CVE-2024-10915. The attackers also used a buffer overflow in the `goform` name parameter across multiple device vendors. ClingSTUN downloaders move to `/tmp`, retrieve architecture-specific payloads, and execute versions for ARM, Intel 80386, MIPS, PowerPC, and AMD x86-64 systems. A later downloader scans `/proc/mounts`, unmounts selected mount points, kills associated processes, and terminates processes running from `/tmp`. The malware also enumerates `/proc`, identifies competing or suspicious processes, compares process command lines with executable names, and kills processes that fail its checks. It opens watchdog device files and uses `ioctl` to disable watchdog timers. For persistence, ClingSTUN copies itself to `/root/.cling` and `/usr/local/bin/.cling`, sets executable permissions, and appends these files to three startup-related files so they execute during boot. It clears its command-line arguments to hide activity from process-monitoring tools. When running as root, it copies selected files from `/proc/1` into `/tmp` and bind-mounts the directory over its own `/proc` entry to conceal process information. The backdoor uses UDP sockets and standard 20-byte STUN binding requests to contact public STUN services, discover externally mapped addresses and ports, and maintain NAT bindings. Earlier versions contacted 24 endpoints and required at least half to respond; a later version used 13 endpoints and required all to succeed. It periodically sends a group identifier and mapped-port data to these services. A specially formatted 20-byte operator packet can trigger remote command execution: command 1 causes the malware to establish an outbound TCP connection, receive a command, and execute it. ClingSTUN also contains hard-coded exploits for self-propagation.

    00000189
    828 followersView on X
  • Dev@computerauditor
    Active Exploitation

    Ivanti Connect Secure 0-day RCE (CVE-2023-46805 &amp; CVE-2024-21887) is WILD. Chained auth bypass + command inj. allows unauth RCE. Patch ASAP! #Cybersecurity #0day https://t.co/WcmR6Fq2DN

    Post summary

    Ivanti Connect Secure vulnerabilities CVE-2023-46805 and CVE-2024-21887 are confirmed to be actively exploited with unauthenticated RCE, and immediate patching is required.

    00000127
    151 followersView on X
  • Dev@computerauditor
    Active Exploitation

    Ivanti Connect Secure RCE (CVE-2024-21887/88) was deadly. SSRF chained with cmd injection gave attackers full VPN control. Critical for ops, patch ASAP. Follow @computerauditor for more. #Ivanti #Exploit https://t.co/YcIl9lnQHA

    Post summary

    The tweet reports that CVE-2024-21887/88 in Ivanti Connect Secure has been actively exploited via SSRF and command injection, granting attackers full VPN control, and urges immediate patching.

    0000077
    148 followersView on X
  • Dev@computerauditor
    Patch

    New FortiClientEMS RCE CVE-2024-21887 (CVSS 9.3)! SQLi in FGXprtLog allows pre-auth RCE. Patch now! Check /EndpointLogon.aspx for exposed instances. #infosec #bugbounty #RCE https://t.co/MjdcEAAt0F

    Post summary

    The tweet alerts about a severe RCE vulnerability (CVE‑2024‑21887) in FortiClientEMS, highlights the availability of a patch, and provides basic technical details.

    0000050
    146 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://lyrie.ai/research/research/active-exploit-cve-2024-21887-connect-secure-and-policy-secure #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    A tweet linking to a research post suggests that CVE‑2024‑21887 is actively being exploited in the wild; no PoC, exploit code, patch, or technical details are disclosed in the brief message.

    0000021
    152 followersView on X
  • 777@SteveAJ777
    General

    I cannot post the full snort rules but u might want to add them, . [CVE-2024-1709] ConnectWise ScreenConnect Authentication Bypass  . [CVE-2024-21887] Ivanti Connect Secure Command Injection  . [CVE-2024-3400] Palo Alto PAN-OS GlobalProtect Command Injection

    Post summary

    The message simply lists three CVE identifiers with brief vulnerability descriptors, without providing PoC code, active exploitation evidence, patches, or debunking claims.

    00000120
    198 followersView on X
  • Dev@computerauditor
    Active Exploitation

    Ivanti VPN zero-days (CVE-2023-46805, CVE-2024-21887) are critical. Chained for unauth RCE. Bug bounty hunters: Look for exposed Ivanti instances via Shodan. Defenders: Patch immediately. Attackers are active. https://t.co/a1wCDamw5F

    Post summary

    The tweet warns of two critical Ivanti VPN zero‑days causing unauthenticated RCE; attackers are actively exploiting them, and immediate patching is urged.

    0000094
    128 followersView on X
CPE platform detail81 entries

81 of 81 entries

PartVendorProductVersionTarget SWTarget HW
Appivanticonnect_secure22.1--
Appivanticonnect_secure22.1--
Appivanticonnect_secure22.2--
Appivanticonnect_secure22.2--
Appivanticonnect_secure22.3--
Appivanticonnect_secure22.4--
Appivanticonnect_secure22.4--
Appivanticonnect_secure22.5--
Appivanticonnect_secure22.6--
Appivanticonnect_secure22.6--
Appivanticonnect_secure22.6--
Appivanticonnect_secure9.0--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivanticonnect_secure9.1--
Appivantipolicy_secure22.1--
Appivantipolicy_secure22.1--
Appivantipolicy_secure22.2--
Appivantipolicy_secure22.2--
Appivantipolicy_secure22.3--
Appivantipolicy_secure22.3--
Appivantipolicy_secure22.4--
Appivantipolicy_secure22.4--
Appivantipolicy_secure22.4--
Appivantipolicy_secure22.5--
Appivantipolicy_secure22.5--
Appivantipolicy_secure22.6--
Appivantipolicy_secure9.0--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--
Appivantipolicy_secure9.1--

Explore more