Ivanti, a leading cybersecurity company, has recently addressed four critical vulnerabilities found in their Connect Secure, Policy Secure, and Cloud Services Applications. These vulnerabilities, labeled as CVE-2024-38657, CVE-2025-22467, CVE-2024-10644, and CVE-2024-47908, pose a severe risk with a severity score of 9.1/10.
These bugs, if exploited, could allow malicious actors to execute arbitrary code remotely, potentially leading to highly disruptive cyberattacks. To mitigate this risk, Ivanti has released patches for the affected products, urging users to apply them urgently. Despite no current evidence of exploitation in the wild, Ivanti products are often targeted by cyber threats, making prompt patching crucial.
Daniel Spicer, Ivanti’s Chief Security Officer, emphasized the importance of proactive measures to safeguard against potential threats. The US Cybersecurity and Infrastructure Security Agency (CISA) has also recognized these vulnerabilities, adding them to their Known Exploited Vulnerabilities catalog.
In conclusion, users are advised to update their Ivanti products to the latest secure versions and stay vigilant against potential cyber threats.