• News/
  • https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-connect-secure-zero-day-exploited-in-attacks/

Ivanti warns of new Connect Secure zero-day exploited in attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 31, 2024
·
Updated

Today, Ivanti warned of two more vulnerabilities impacting Connect Secure, Policy Secure, and ZTA gateways, one of them a zero-day bug already under active exploitation. The zero-day flaw (CVE-2024-21893) is a server-side request forgery vulnerability in the gateways' SAML component that enables attackers to bypass authentication and access restricted resources on vulnerable devices. A second flaw (CVE-2024-21888) in the gateways' web component allows threat actors to escalate privileges to those of an administrator. "As part of our ongoing investigation into the vulnerabilities reported on 10 January in Ivanti Connect Secure, Ivanti Policy Secure and ZTA gateways, we have discovered new vulnerabilities. These vulnerabilities impact all supported versions – Version 9.x and 22.x," the company said today. "We have no evidence of any customers being impacted by CVE-2024-21888 at this time. We are only aware of a small number of customers who have been impacted by CVE-2024-21893 at this time." "It is critical that you immediately take action to ensure you are fully protected," Ivanti warned. Ivanti has released security patches to address both flaws for some affected ZTA and Connect Secure versions, and it provides mitigation instructions for devices still waiting for a patch. The company also released patches today for two other zero-days disclosed in early January— an authentication bypass (CVE-2023-46805) and a command injection (CVE-2024-21887)—chained in widespread attacks ...

Read full article

Affected Software

4 affected components
Ivanti Connect Secure=9.x
Ivanti Connect Secure=22.x
Ivanti Policy Secure
Ivanti ZTA gateways
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new zero-day vulnerability in Ivanti's Connect Secure and related products that is currently being exploited in attacks.

2

What security implications are discussed in this article?

The article highlights the risk of exploitation due to the discovered server-side request forgery vulnerability in Ivanti's software.

3

What specific vulnerabilities are mentioned in the article?

The article mentions a zero-day vulnerability identified as CVE-2024-21893, along with two additional vulnerabilities impacting Ivanti products.

4

What products or software are affected by the vulnerabilities?

Affected products include Ivanti Connect Secure (versions 9.x and 22.x), Ivanti Policy Secure, and Ivanti ZTA gateways.

5

What action should users of affected Ivanti products take?

Users of the affected Ivanti products are urged to apply available patches and monitor their systems for any unusual activity.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203