• News/
  • https://www.bleepingcomputer.com/news/security/cisa-emergency-directive-mitigate-ivanti-zero-days-immediately/

CISA emergency directive: Mitigate Ivanti zero-days immediately

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 19, 2024
·
Updated

CISA issued this year's first emergency directive ordering Federal Civilian Executive Branch (FCEB) agencies to immediately mitigate two Ivanti Connect Secure and Ivanti Policy Secure zero-day flaws in response to widespread and active exploitation by multiple threat actors. This is an expected development, given that vulnerable Ivanti appliances are now targeted in extensive attacks chaining the CVE-2023-46805 authentication bypass and the CVE-2024-21887 command injection vulnerabilities since December, and the vendor has yet to release security patches. When chained, the two Ivanti zero-days allow attackers to move laterally within a target's network, exfiltrate data, and establish persistent system access by deploying backdoors. "CISA has determined these conditions pose an unacceptable risk to Federal Civilian Executive Branch (FCEB) agencies and require emergency action," the cybersecurity agency said on Friday. "This determination is based on widespread exploitation of vulnerabilities by multiple threat actors, the prevalence of the affected products in the federal enterprise, the high potential for a compromise of agency information systems, the impact of a successful compromise, and the complexity of the proposed mitigations." As instructed by emergency directive ED 24-01, federal agencies now must promptly implement Ivanti's publicly disclosed mitigation measures to block attack attempts. The agencies are also required to use Ivanti's External Integrity Checker Tool...

Read full article

Affected Software

2 affected components
Ivanti Connect Secure
Ivanti Policy Secure
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses CISA's emergency directive for mitigating Ivanti zero-day vulnerabilities.

2

What security implications are discussed in the article?

The article highlights the urgent need to address critical zero-day flaws in Ivanti software to prevent potential exploitation.

3

What products are affected by the zero-day vulnerabilities?

The affected products are Ivanti Connect Secure and Ivanti Policy Secure.

4

Who is mandated to take action according to the directive?

Federal Civilian Executive Branch (FCEB) agencies are mandated to take immediate action.

5

What actions are recommended by CISA in response to the vulnerabilities?

CISA recommends immediate mitigation measures to address the Ivanti zero-day flaws.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203