U.S. CISA adds new Ivanti Cloud Services Appliance Vulnerability to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 25, 07:42 UTC · Sep 25, 2024Exploit / PoC in the wildCVE-2024-8190CVE-2024-896360
U.S. CISA adds Ivanti Cloud Services Appliance Vulnerability to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 14, 15:45 UTC · Sep 14, 2024Exploit / PoC in the wildCVE-2024-819060
PoC exploit for exploited Ivanti Cloud Services Appliance flaw released (CVE-2024-8190)Help Net Security·Sep 19, 20:44 UTC · Sep 19, 2024Exploit / PoC in the wildCVE-2024-8190CVE-2024-896360
Ivanti Cloud Service Appliance flaw is being actively exploitedSecurity Affairs·Sep 14, 10:32 UTC · Sep 14, 2024Exploit / PoC in the wildCVE-2024-8190CVE-2024-2984760
Ivanti warns of a new actively exploited Cloud Services Appliance (CSA) flawSecurity Affairs·Sep 19, 20:49 UTC · Sep 19, 2024Exploit / PoC in the wildCVE-2024-8963CVE-2024-819060
Ivanti provides temporary patches for actively exploited EPMM zero-day (CVE-2026-1281)Help Net Security·Feb 2, 10:44 UTC · Feb 2, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-134060
French cybersecurity agency confirms government affected by Ivanti hacksThe Record·Jul 2, 12:09 UTC · Jul 2, 2025Exploit / PoCCVE-2024-8190CVE-2024-8963CVE-2024-938060
Researchers Identify Multiple China Hacker Groups Exploiting Ivanti Security FlawsThe Hacker News·Apr 6, 09:12 UTC · Apr 6, 2024Exploit / PoCCVE-2023-46805CVE-2024-21887CVE-2024-2189360
Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates ReleasedThe Hacker News·Apr 9, 04:57 UTC · Apr 9, 2026Exploit / PoC in the wildCVE-2026-1281CVE-2026-134060
New zeroCyberScoop·Jan 9, 21:51 UTC · Jan 9, 2025Exploit / PoC in the wildCVE-2025-0282CVE-2025-028360
Zero-days exploited in the wild jumped 50% in 2023, fueled by spyware vendorsThe Record·Mar 27, 01:56 UTC · Mar 27, 2024Exploit / PoC in the wildCVE-2023-4863CVE-2023-41064CVE-2023-521760
Zero-day exploitation surged in 2023, Google findsHelp Net Security·Mar 28, 00:00 UTC · Mar 28, 2024Exploit / PoC in the wild60
China-linked group Houken hit French organizations using zeroSecurity Affairs·Jul 3, 18:16 UTC · Jul 3, 2025Exploit / PoCCVE-2024-8963CVE-2024-938060
U.S. CISA adds Ivanti CSA and Fortinet bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Oct 10, 11:11 UTC · Oct 10, 2024Exploit / PoC in the wildCVE-2024-23113CVE-2024-9379CVE-2024-9380+2 CVEs60
Critical Ivanti ZeroInfosecurity Magazine·Jan 9, 09:45 UTC · Jan 9, 2025Exploit / PoC in the wildCVE-2025-0282CVE-2025-028360
Ivanti Connect Secure zero-day exploited by attackers (CVE-2025-0282)Help Net Security·Jan 8, 00:00 UTC · Jan 8, 2025Exploit / PoCCVE-2025-0282CVE-2025-028360
Three new Ivanti CSA zeroSecurity Affairs·Oct 8, 21:26 UTC · Oct 8, 2024Exploit / PoC in the wildCVE-2024-9379CVE-2024-9380CVE-2024-9381+2 CVEs60
Five Eyes alliance warns of attacks exploiting known Ivanti Gateway flawsSecurity Affairs·Mar 1, 14:01 UTC · Mar 1, 2024Exploit / PoCCVE-2023-46805CVE-2024-21887CVE-2024-21893+2 CVEs60
Ivanti Connect Secure zero-day exploited since mid-December (CVE-2025-0282)Help Net Security·Jan 9, 00:00 UTC · Jan 9, 2025Exploit / PoCCVE-2025-028260
Recent SSRF Flaw in Ivanti VPN Products Undergoes Mass ExploitationThe Hacker News·Feb 6, 14:36 UTC · Feb 6, 2024Exploit / PoC in the wildCVE-2024-21893CVE-2024-21887CVE-2023-36661+1 CVEs60
Palo Alto firewalls: CVE-2024-3400 exploitation and PoCs for persistence after resets/upgradesHelp Net Security·May 6, 08:12 UTC · May 6, 2024Exploit / PoC in the wildCVE-2024-340060
PoC exploit for Ivanti Endpoint Manager vulnerabilities released (CVE-2024-13159)Help Net Security·Feb 24, 00:00 UTC · Feb 24, 2025Exploit / PoC in the wildCVE-2024-13159CVE-2024-10811CVE-2024-13161+1 CVEs60
CISA adds FortiClient EMS, Ivanti EPM CSA, Nice Linear eMerge E3-Series bugs to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 25, 20:52 UTC · Mar 25, 2024Exploit / PoC in the wildCVE-2023-48788CVE-2021-44529CVE-2019-725660
China-linked attacker hit France’s critical infrastructure via trio of Ivanti zeroCyberScoop·Jul 3, 16:02 UTC · Jul 3, 2025Exploit / PoC in the wildCVE-2024-8190CVE-2024-8963CVE-2024-938060
U.S. CISA adds Ivanti Sentry flaw to its Known Exploited Vulnerabilities catalog and urges patching by June 14Security Affairs·Jun 14, 13:16 UTC · Jun 14, 2026Exploit / PoC in the wildCVE-2026-1052060
U.S. CISA adds Ivanti Connect Secure, Policy Secure, and ZTA Gateways flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Jan 9, 11:53 UTC · Jan 9, 2025Exploit / PoC in the wildCVE-2025-0282CVE-2025-028360
Ivanti Pulse Secure Found Using 11-YearThe Hacker News·Feb 15, 00:00 UTC · Feb 15, 2024Exploit / PoC in the wildCVE-2023-46805CVE-2024-21887CVE-2024-21893+1 CVEs60
Rust Payloads Exploiting Ivanti 0Infosecurity Magazine·Jan 30, 15:00 UTC · Jan 30, 2024Exploit / PoCCVE-2024-21887CVE-2023-4680560
RedNovember Targets Government, Defense, and Technology OrganizationsRecorded Future·Nov 14, 00:00 UTC · Nov 14, 2024Exploit / PoC in the wild60
Chinese Hackers Target France in Ivanti ZeroInfosecurity Magazine·Jul 2, 12:00 UTC · Jul 2, 2025Exploit / PoCCVE-2024-8190CVE-2024-8963CVE-2024-9380160
Ongoing attacks on Ivanti VPNs install a ton of sneaky, wellArs Technica · Security·Jan 9, 22:17 UTC · Jan 9, 2025Exploit / PoC in the wildCVE-2025-028260
Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, TelecomsThe Hacker News·Jul 3, 09:25 UTC · Jul 3, 2025Exploit / PoC in the wildCVE-2024-8963CVE-2024-9380CVE-2024-819060
Cisco Warns of Critical Flaw Affecting OnThe Hacker News·Jul 18, 13:13 UTC · Jul 18, 2024Exploit / PoC in the wildCVE-2024-20419CVE-2024-20401CVE-2024-34102+2 CVEs60
A PoC exploit code is available for critical Ivanti vTM bugSecurity Affairs·Aug 13, 18:06 UTC · Aug 13, 2024Exploit / PoCCVE-2024-759360
CISA orders Ivanti devices targeted by Chinese hackers be disconnectedCyberScoop·Feb 1, 20:30 UTC · Feb 1, 2024Exploit / PoC in the wildCVE-2024-2188760
Chinese State Hackers Exploiting Newly Disclosed Ivanti FlawInfosecurity Magazine·Apr 4, 11:04 UTC · Apr 4, 2025Exploit / PoC in the wildCVE-2025-2245760
Ivanti: Three CSA ZeroInfosecurity Magazine·Oct 9, 10:15 UTC · Oct 9, 2024Exploit / PoC in the wildCVE-2024-9379CVE-2024-9380CVE-2024-9381+2 CVEs60
DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025The Hacker News·Apr 25, 08:43 UTC · Apr 25, 2025Exploit / PoC in the wildCVE-2025-0282CVE-2025-2245760
U.S. CISA adds Ivanti Virtual Traffic Manager flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs·Sep 25, 08:08 UTC · Sep 25, 2024Exploit / PoC in the wildCVE-2024-759360
Ivanti fixes three CSA zero-days exploited in the wild (CVE-2024-9379, CVE-2024-9380, CVE-2024-9381)Help Net Security·Jan 23, 10:55 UTC · Jan 23, 2025Exploit / PoC in the wildCVE-2024-9379CVE-2024-9380CVE-2024-9381+2 CVEs60