CVE-2023-46805

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 22 articles

EPSS Score

Source: FIRST.org · 2026-05-24
94.37%
probability
This CVE has a 94.37% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE. View on VulnerabilityLookup ↗

Attack Intelligence

Exploits & PoC

duy-31/CVE-2023-46805_CVE-2024-21887

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restri

23
Chocapikk/CVE-2023-46805

Ivanti Pulse Secure CVE-2023-46805 Scanner - Based on Assetnote's Research

13
seajaysec/Ivanti-Connect-Around-Scan

Mitigation validation utility for the Ivanti Connect Around attack chain. Runs multiple checks. CVE-2023-46805, CVE-2024-21887.

12
yoryio/CVE-2023-46805

Scanner for CVE-2023-46805 - Ivanti Connect Secure

10
cbeek-r7/CVE-2023-46805

Simple scanner for scanning a list of ip-addresses for vulnerable Ivanti Pulse Secure devices

5
Hexastrike/Ivanti-Connect-Secure-Logs-Parser

A Python script for examining Ivanti Secure Connect (ICS) event logs, designed to support investigations into vulnerabilities CVE-2025-0282, CVE-2023-

5
raminkarimkhani1996/CVE-2023-46805_CVE-2024-21887

The script in this repository only checks whether the vulnerabilities specified in the Ivanti Connect Secure product exist.

5
w2xim3/CVE-2023-46805

CVE-2023-46805 Ivanti POC RCE - Ultra fast scanner.

2
rxwx/pulse-meter

Parses the System Snapshot from an Ivanti Connect Secure applicance to identify possible IOCs related to CVE-2023-46805, CVE-2024-21887 and CVE-2025-0

1
9 repos — triés par ⭐ Rechercher sur GitHub ↗
Security Advisory 2024-004
CERT-EU Feb 09, 2024

Signal Intelligence

Confidence
92%
EPSS 94.37%
Mentions 22
Last Seen May 27, 2026

CNA Information

Analyst Note

CVE-2023-46805 is explicitly named as a zero-day exploited in the wild across multiple authoritative sources (BleepingComputer, CISA emergency directive). Articles document active attacks and simultaneous patch availability, with exploitation reported since mid-March 2024 and mass exploitation following disclosure. Clear zero-day criteria met.

Threat Actors 47

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
Turla Group
apt_group Information theft and espionage Russian Federation
APT 29
apt_group Information theft and espionage 🇷🇺 RU
DarkHotel
apt_group Information theft and espionage 🇰🇷 KR
APT27
apt_group Information theft and espionage 🇨🇳 CN
Cobalt
apt_group Financial crime 🇷🇺 RU
APT 28
apt_group Information theft and espionage 🇷🇺 RU
Kimsuky
apt_group Information theft and espionage 🇰🇷 KR
EMISSARY PANDA
apt_group Information theft and espionage 🇨🇳 CN
Harvester
apt_group Information theft and espionage Unknown
Hacking Team
apt_group 🇮🇹 IT
GhostEmperor
apt_group Information theft and espionage 🇨🇳 CN
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
Tick
apt_group Information theft and espionage 🇨🇳 CN
APT3
apt_group Information theft and espionage 🇨🇳 CN
ELECTRUM
apt_group Information theft and espionage 🇷🇺 RU
Infy
apt_group Information theft and espionage 🇮🇷 IR
Volt Typhoon
apt_group Information theft and espionage 🇨🇳 CN
SideCopy
apt_group Information theft and espionage 🇵🇰 PK
ArcaneDoor
apt_group 🇨🇳 CN
TA428
apt_group Information theft and espionage 🇨🇳 CN
APT42
apt_group Information theft and espionage 🇮🇷 IR
SideWinder
apt_group 🇮🇳 IN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
FamousSparrow
apt_group Information theft and espionage 🇨🇳 CN
RomCom
apt_group Financial gain 🇷🇺 RU
HAFNIUM
apt_group Information theft and espionage 🇨🇳 CN
Fox Kitten
apt_group Information theft and espionage 🇮🇷 IR
UTA0178
apt_group Information theft and espionage 🇨🇳 CN
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Flax Typhoon
apt_group Information theft and espionage 🇨🇳 CN
Operation Cobalt Whisper
apt_group Financial crime 🇨🇳 CN
Void Rabisu
apt_group Financial gain 🇷🇺 RU
UNC4841
apt_group Information theft and espionage 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
UAC-0184
apt_group 🇺🇦 UA
Red Dev 17
apt_group 🇨🇳 CN
Red October
apt_group 🇷🇺 RU
Patched Lightning
apt_group 🇬🇭 GH
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Iron Group
apt_group Information theft and espionage 🇨🇳 CN
UNC5337
apt_group 🇨🇳 CN
Big Panda
apt_group 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Beijing Group
apt_group Information theft and espionage 🇨🇳 CN
Storm-0558
apt_group Information theft and espionage 🇨🇳 CN

Triage Info

Decided atMar 05, 2026