CVE-2024-9380
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
5 articles
EPSS Score
Source: FIRST.org · 2026-05-24
86.91%
probability
This CVE has a 86.91% probability
of being exploited in the next 30 days.
0%
Top 99.4th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Ivanti warns of three more CSA zero-days exploited in attacks
BleepingComputer
Oct 08, 2024
Chinese Hackers Exploit Ivanti CSA Zero-Days in Attacks on French Government, Telecoms
TheHackerNews
Signal Intelligence
Confidence
85%
EPSS
86.91%
Mentions
5
Last Seen
Oct 22, 2024
CNA Information
Analyst Note
CVE-2024-9380 is explicitly named as a zero-day being exploited in the wild by Ivanti's official warning ('three more CSA zero-days exploited in attacks'). Published October 8, 2024, with contemporaneous exploitation reports, and confirmed by CERT-FR advisory on October 22, 2024 documenting active exploitation. The timing and authoritative naming meet zero-day criteria.
Threat Actors 12
APT 41
apt_group
Information theft and espionage
🇨🇳 CN
APT 29
apt_group
Information theft and espionage
🇷🇺 RU
Hacking Team
apt_group
🇮🇹 IT
Infy
apt_group
Information theft and espionage
🇮🇷 IR
Group 27
apt_group
Information theft and espionage
🇨🇳 CN
UNC5174
apt_group
🇨🇳 CN
Chimera
apt_group
Information theft and espionage
🇨🇳 CN
Red October
apt_group
🇷🇺 RU
Mana Team
apt_group
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Beijing Group
apt_group
Information theft and espionage
🇨🇳 CN
PlushDaemon
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 05, 2026