Authentication Bypass in Ivanti Connect Secure and Policy Secure Web Component
CISA: Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
CVSS 3.1
8.2high
EPSS
100%p100
Published
()
KEV added
AI analysis
Ivanti Connect Secure (ICS, formerly Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass (CWE-287) in the web component that allows an attacker to access restricted resources by bypassing control checks without valid credentials. The flaw is triggered through the exposed web interface of the gateway, and it is most dangerous when chained with CVE-2024-21887, a command injection vulnerability in the same component, which turns the bypass into unauthenticated arbitrary command execution on the appliance. An attacker gains access to protected resources and, via the chained command injection, the ability to run commands on the gateway — the pattern observed in the January 2024 exploitation wave that led to follow-on compromise, including known ransomware use. Affected organizations are those running Ivanti Connect Secure or Policy Secure gateways, which are typically deployed as internet-facing VPN concentrators at the network edge. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2024-01-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile); no CVSS score is available yet and no public PoC is known.
What to do: Apply Ivanti's mitigations or patched builds per the vendor's instructions immediately, or discontinue use of the product if mitigations are unavailable, as CISA's KEV required action states, and remediate the companion command injection flaw CVE-2024-21887 on the same gateways. Because exploitation is confirmed in the wild with known ransomware use, treat any long-running appliance as potentially compromised: check it for signs of compromise per vendor guidance and rotate credentials, sessions, and any secrets stored on or reachable through the VPN.
largetens of thousands of internet-exposed gateways (public internet-wide scans around the January 2024 disclosure found on the order of 20,000-30,000 exposed… — These gateways are edge VPN appliances that are commonly directly reachable from the internet, and public scan counts around disclosure indicated an exposed installed base in the low tens of thousands, with Policy Secure deployments…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.
CISA Known Exploited Vulnerability
Affected
Ivanti Connect Secure and Policy Secure
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Microsoft reports China-linked ransomware group Storm-1175 switched from Medusa to a new C++ strain, StormEncryptor, likely exploiting N-able flaw CVE-2026-18577.
Microsoft Threat Intelligence reports that the financially motivated, China-linked group Storm-1175 began deploying a new ransomware strain called StormEncryptor on August 2, 2026, replacing its previous Medusa ransomware. StormEncryptor is written in C++, appends the .encrypted extension to files, and drops a !!!README_FIRST!!!.txt ransom note in each scanned directory. Microsoft assesses the group is likely exploiting CVE-2026-18577, an authentication bypass in N-able disclosed on August 2, 2026 and added to CISA's Known Exploited Vulnerabilities catalog the next day. Since 2023, Storm-1175 has exploited more than 16 vulnerabilities in products including Microsoft Exchange, Ivanti, ConnectWise ScreenConnect, JetBrains TeamCity, SimpleHelp, CrushFTP, and GoAnywhere MFT, often moving from initial access to data theft and ransomware deployment within days.