Security News > 2024 > January > Ivanti warns of new Connect Secure zero-day exploited in attacks

Ivanti warns of new Connect Secure zero-day exploited in attacks
2024-01-31 13:41

Today, Ivanti warned of two more vulnerabilities impacting Connect Secure, Policy Secure, and ZTA gateways, one of them a zero-day bug already under active exploitation.

"As part of our ongoing investigation into the vulnerabilities reported on 10 January in Ivanti Connect Secure, Ivanti Policy Secure and ZTA gateways, we have discovered new vulnerabilities. These vulnerabilities impact all supported versions - Version 9.x and 22.x," the company said today.

Ivanti has released security patches to address both flaws for some affected ZTA and Connect Secure versions, and it provides mitigation instructions for devices still waiting for a patch.

Ivanti Connect Secure zero-days now under mass exploitation.

Ivanti warns of Connect Secure zero-days exploited in attacks.

CISA: Critical Ivanti auth bypass bug now actively exploited.


News URL

https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-connect-secure-zero-day-exploited-in-attacks/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Ivanti 23 9 60 74 51 194