References https://www.akamai.com/zh/blog/security-research/ivanti-january-rce-cve-zero-day-exploitation-observed https://blog.cloudflare.com/zh-cn/how-cloudflares-ai-waf-proactively-detected-ivanti-connect-secure-critical-zero-day-vulnerability/ https://www.anquanke.com/post/id/292693 https://x.threatbook.com/v5/article?threatInfoID=100828 https://www.fortiguard.com/cn/outbreak-alert/ivanti-authentication-bypass https://www.aqtd.com/nd.jsp?id=5928 https://cloud.tencent.com/developer/article/2382130 https://www.zzwa.org.cn/7147/ https://www.4hou.com/posts/JK3y https://www.anquan114.com/archives/1361 https://cn.info-sec.wiki/?p=1947 https://blog.billows.com.tw/?tag=cisa https://www.tenablecloud.cn/plugins/updated?type=nessus&page=77 https://www.reddit.com/r/sysadmin/comments/193ki7n/active_exploitation_of_two_zeroday/ https://www.reddit.com/r/cybersecurity/comments/193k7c1/active_exploitation_of_two_zeroday/ https://cloud.tencent.com/developer/article/2385580 https://www.fortisec.co.uk/blog/cve-2023-46805-ivanti https://research.splunk.com/stories/ivanti_connect_secure_vpn_vulnerabilities/ https://pentera.io/blog/ivanti-zero-day-vulnerabilities-understand-your-impact/ https://www.assetnote.io/resources/research/high-signal-detection-and-exploitation-of-ivantis-pulse-connect-secure-auth-bypass-rce https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/ https://github.com/raminkarimkhani1996/CVE-2023-46805_CVE-2024-21887 https://securestep9.medium.com/detecting-ivanti-cve-2023-46805-with-owasp-nettacker-v0-3-3-857690624a3c https://www.northwave-cybersecurity.com/whitepapers-articles/investigating-a-possible-ivanti-compromise https://www.uvcyber.com/hubfs/downloadable-content/product-sheets/Ivanti%20Vulnerabilities.pdf https://www.cisa.gov/news-events/directives/ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure-vulnerabilities https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways
Related VulnerabilitiesPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2026-10520: Ivanti Sentry - OS Command InjectionIvanti Sentry存在操作系统命令注入漏洞(CVE-2026-10520)Ivanti Sentry /mics/api/v2/sentry/mics-config/handleMessage 命令执行漏洞(CVE-2026-10520)Ivanti EPMM /mifs/rs/api/v2/featureusage 命令执行漏洞(CVE-2025-4427)PoCIvanti Endpoint Manager /RemoteControlAuth/api/Auth 权限绕过漏洞(CVE-2026-1603)Ivanti Endpoint Manager 权限管理不当漏洞PoCCVE-2026-1603: Ivanti Endpoint Manager - Authentication BypassIvanti Endpoint Manager Mobile /mifs/c/appstore/fob/3/5/sha256 命令执行漏洞(CVE-2026-1281/CVE-2026-1340)Ivanti Endpoint Manager Mobile 未授权 代码注入漏洞Ivanti多个产品跨站请求伪造漏洞(CVE-2025-8711)(CVE-2025-8712)Ivanti产品权限验证不足漏洞