CVE-2024-21893

Exploited in the Wild ✓ Confirmed 0-Day
Triaged: March 5, 2026 10 articles Published: 2024-01-31

EPSS Score

Source: FIRST.org · 2026-05-24
94.32%
probability
This CVE has a 94.32% probability of being exploited in the next 30 days.
0% Top 100.0th percentile of all CVEs 100%

CVSS v3.0

Source: VulnerabilityLookup (CIRCL)
8.2
HIGH
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Description

VulnerabilityLookup (CNA)
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

Affected Products

Ivanti
ICS
9.1R18 22.6R2
Ivanti
IPS
9.1R18 22.6R1

Attack Intelligence

Exploits & PoC

h4x0r-dz/CVE-2024-21893.py

CVE-2024-21893: SSRF Vulnerability in Ivanti Connect Secure

95
Chocapikk/CVE-2024-21893-to-CVE-2024-21887

CVE-2024-21893 to CVE-2024-21887 Exploit Toolkit

26
2 repos — triés par ⭐ Rechercher sur GitHub ↗

Signal Intelligence

Confidence
92%
EPSS 94.32%
CVSS v3.0 8.2
Mentions 10
Last Seen Aug 06, 2024

CNA Information

CNA Assigner
hackerone

Analyst Note

CVE-2024-21893 is explicitly named as a zero-day being exploited in attacks by Ivanti and reported by BleepingComputer. Published 2024-01-31 with active exploitation documented in early 2024. No evidence of prior patch availability before exploitation reports. Clear zero-day exploitation confirmation.

Threat Actors 28

Lazarus Group
apt_group Information theft and espionage 🇰🇵 KP
DarkHotel
apt_group Information theft and espionage 🇰🇷 KR
Harvester
apt_group Information theft and espionage Unknown
Lotus Blossom
apt_group Information theft and espionage 🇨🇳 CN
SCATTERED SPIDER
apt_group Financial crime 🇺🇸 US
Infy
apt_group Information theft and espionage 🇮🇷 IR
Volt Typhoon
apt_group Information theft and espionage 🇨🇳 CN
SideCopy
apt_group Information theft and espionage 🇵🇰 PK
ArcaneDoor
apt_group 🇨🇳 CN
TA428
apt_group Information theft and espionage 🇨🇳 CN
SideWinder
apt_group 🇮🇳 IN
RAZOR TIGER
apt_group Information theft and espionage 🇮🇳 IN
[Unnamed group]
apt_group 🇨🇳 CN
Fox Kitten
apt_group Information theft and espionage 🇮🇷 IR
UTA0178
apt_group Information theft and espionage 🇨🇳 CN
APT 22
apt_group Information theft and espionage 🇨🇳 CN
Rocke
apt_group 🇨🇳 CN
APT 6
apt_group Information theft and espionage 🇨🇳 CN
UAC-0184
apt_group 🇺🇦 UA
Red October
apt_group 🇷🇺 RU
Shadow Network
apt_group Information theft and espionage 🇨🇳 CN
Mana Team
apt_group 🇨🇳 CN
Iron Group
apt_group Information theft and espionage 🇨🇳 CN
Operation Shadow Force
apt_group 🇨🇳 CN
Sabre Panda
apt_group 🇨🇳 CN
Operation Dragon Castling
apt_group Information theft and espionage 🇨🇳 CN
APT 5
apt_group Information theft and espionage 🇨🇳 CN
Operation Black Atlas
apt_group Financial crime

Triage Info

Decided atMar 05, 2026
Published DateJan 31, 2024