"Ivanti Zero-Day Vulnerabilities Spark Security Concerns"

1 min read
Source: The Hacker News
"Ivanti Zero-Day Vulnerabilities Spark Security Concerns"
Photo: The Hacker News
TL;DR

Ivanti has disclosed two new high-severity zero-day flaws in its Connect Secure and Policy Secure products, with one already being actively exploited. The vulnerabilities include a privilege escalation flaw and a server-side request forgery issue. Ivanti has released fixes for the affected versions and recommends customers to factory reset their appliance before applying the patch. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an advisory warning about adversaries leveraging these flaws to capture credentials and compromise enterprise networks.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News