U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Cloud Services Appliance Vulnerability to its Known Exploited Vulnerabilities catalog.
The vulnerability, tracked as CVE-2024-8963, is actively exploited in attacks against a limited number of customers.
An attacker could exploit the vulnerability to access restricted functionality and execute arbitrary commands on the appliance.
CISA orders federal agencies to fix this vulnerability by October 10, 2024.