Zero-Day Alert: Three Critical Ivanti CSA Vulnerabilities Actively Exploited
Three new security flaws affecting Ivanti's Cloud Service Appliance (CSA) have been actively exploited in the wild, the company has said.
The zero-day defects are being weaponized in conjunction with another flaw in CSA that the business addressed last month, the Utah-based software services provider said.
If these vulnerabilities are successfully exploited, an authorized attacker with administrator credentials may be able to execute arbitrary SQL statements, circumvent security measures, and get remote code execution.
A small number of users running CSA 4.6 patch 518 and earlier, according to the firm, have been known to have been taken advantage of when CVE-2024-9379, CVE-2024-9380, or CVE-2024-9381 are chained with CVE-2024-8963 read more about Three Critical Ivanti CSA Vulner...


