CVE-2024-21887: listed in the CISA KEV catalog CVE-2024-21887 · CVSS 9.1 CRITICAL · EPSS 100.0% · KEV 2024-01-10
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Is CVE-2024-21887 exploited? Listed in the CISA KEV catalog on 2024-01-10. Federal remediation due 2024-01-22. Past that date by 936 days. Used in ransomware campaigns. EPSS puts exploitation in the next 30 days at 100.0%. Public exploit code: packaged in a public tool. Public detection rules exist. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2024-21887 Primary sources What this record does not say No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-08-11.
CVE-2024-21887: listed in the CISA KEV catalog CVE-2024-21887 · CVSS 9.1 CRITICAL · EPSS 100.0% · KEV 2024-01-10
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Is CVE-2024-21887 exploited? Listed in the CISA KEV catalog on 2024-01-10. Federal remediation due 2024-01-22. Past that date by 936 days. Used in ransomware campaigns. EPSS puts exploitation in the next 30 days at 100.0%. Public exploit code: packaged in a public tool. Public detection rules exist. Which products and versions are affected? No affected package list recorded here yet.
Is there a patch? No patch identifier recorded here yet.
What PlainSec published about CVE-2024-21887 Primary sources What this record does not say No affected package data. No patch identifier. KEV and EPSS are re-checked daily. Record last updated 2026-08-11.