When you purchase through links on our site, we may earn an affiliate commission.Heres how it works.

Furthermore, they are urged to audit privilege level access accounts, too.

Releasing a security advisory at the time, Ivanti said the flaws were tracked as CVE-2023-46805, and CVE-2024-21887.

Zero-day attack

(Image credit: Shutterstock)

The former is an authentication bypass, while the latter code injection.

They also have until February 5 to report their actions and status to CISA.

ViaBleepingComputer

More from TechRadar Pro