Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityend-of-life-softwareperimeter-device-exposurewidely-deployed-product-advisory

CISA Orders Removal of End-of-Life Ivanti CSA After Active Exploitation

Updated 28d agoFirst seen May 25, 20264 sources

CISA warned that Ivanti Cloud Services Appliance (CSA) was being actively targeted and directed federal civilian agencies to either upgrade to a supported version or remove end-of-life devices from their networks. The order followed Ivanti’s release of a security update for CSA addressing CVE-2024-8190, while CISA said unsupported appliances posed heightened risk because they no longer receive security fixes and were being hit in multiple attacks.

The action came amid broader concern over Ivanti appliance compromises, after earlier emergency guidance and vendor recovery steps tied to CVE-2023-46805 and CVE-2024-21887 showed how attackers could gain access and require full remediation measures. Together, the advisories underscored a continuing pattern in which internet-facing Ivanti appliances became high-priority targets, prompting agencies and enterprises to patch supported systems quickly and retire obsolete deployments.

Share:
CISA Orders Removal of End-of-Life Ivanti CSA After Active Exploitation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Sep 14, 20242y ago

CISA orders federal agencies to upgrade or remove end-of-life Ivanti appliance

Following multiple attacks involving an end-of-life Ivanti product, CISA directed federal civilian agencies to either upgrade the affected appliance to a supported version or remove it from networks. The order reflected escalating concern over continued exploitation risk.

Sep 13, 20242y ago

Ivanti releases security update for Cloud Services Appliance

Ivanti released a security update for its Cloud Services Appliance to address CVE-2024-8190. CISA issued an alert the same day urging organizations to review Ivanti's advisory and apply the update.

Sep 10, 20242y ago

Ivanti publishes CSA advisory for CVE-2024-8190

Ivanti published a security advisory for Cloud Services Appliance vulnerability CVE-2024-8190, documenting the issue and vendor guidance for customers. The advisory formalized details around the flaw and remediation steps.

Jan 16, 20242y ago

Ivanti publishes recovery steps for exploited Connect Secure flaws

Ivanti published recovery guidance related to CVE-2023-46805 and CVE-2024-21887, indicating active response measures for affected appliances. The guidance focused on recovery actions for customers impacted by the vulnerabilities.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.