LIVE MONITORING
Critical Zero-Day CVE-2024-21887

Critical: Ivanti Connect Secure RCE Actively Exploited

Affected Systems

Ivanti Connect Secure 9.x, 22.x; Ivanti Policy Secure

Multiple threat actors are actively exploiting chained vulnerabilities in Ivanti Connect Secure VPN appliances. The vulnerabilities allow unauthenticated remote code execution and have been used to deploy web shells and backdoors.

CISA has issued an emergency directive requiring all federal agencies to disconnect affected products.

Mitigation Steps

  1. Apply Ivanti patches immediately
  2. Reset all VPN user credentials
  3. Check for indicators of compromise
  4. Review logs for unauthorized access since December 2023