spot_img
spot_imgspot_img
April 18, 2026 - 7:51 AM

Global Cyberattack Exploits Zero-Day Flaws in Ivanti’s VPN

—

In a widespread cyber assault, hackers are capitalizing on two zero-day vulnerabilities (CVE-2023-46805 and CVE-2024-21887) within Ivanti’s widely used corporate VPN appliance, Connect Secure.

Volexity has reported mass exploitation, affecting over 1,700 appliances globally and impacting critical industries such as aerospace, banking, defense, government, and telecommunications.

Victims span from small businesses to Fortune 500 companies worldwide, raising concerns about the scale and severity of the attack.

The Shadowserver Foundation estimates that over 17,000 internet-visible Ivanti VPN appliances are at risk globally, with 5,000 situated in the United States.

Ivanti, confirming the mass-hacks, acknowledged increased threat activity commencing on January 11, following the disclosure of vulnerabilities on January 10.

Despite the ongoing exploitation, Ivanti has outlined plans to release patches in a “staggered” manner, with the initial rollout scheduled for the week of January 22.

In the interim, administrators are strongly advised to implement mitigation measures outlined by Ivanti.

These measures include resetting passwords and API keys, as well as revoking and reissuing certificates on affected appliances. 

Doris Israel Ijeoma
Doris Israel Ijeoma
Doris Israel Ijeoma is a graduate of the Nigerian Institute of Journalism, Lagos. She writes Tech, Political, Business and Entertainment Articles. dorisisrael5@gmail.com

1 COMMENT

0 0 votes
Article Rating
Subscribe
Notify of
1 Comment
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
Rose
Rose
7 months ago

Thanks a lot for the article! It was really helpful!

Share post:

Subscribe

Latest News

More like this
Related

APC And its Antics For Revolution In Nigeria

“Circumstances can be changed by revolution and revolutions are...

BREAKING: Iran Reopens Strait of Hormuz Following Ceasefire Deal

Iran has announced the full reopening of the Strait...

BREAKING: Candidates on Edge as JAMB Releases First 2026 UTME Before Midnight

The Joint Admissions and Matriculation Board (JAMB) has confirmed...

US Singer d4vd Arrested After Police Find Teen’s Remains in Tesla Linked to Him

American singer, d4vd, whose legal name is David Anthony...
Join us on
For more updates, columns, opinions, etc.
WhatsApp
1
0
Would love your thoughts, please comment.x
()
x