← CVE Tracker
8.2HIGHCISA KEV — actively exploited

CVE-2023-46805 — An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy…

Ivanti · Connect Secure · Published 12 Jan 2024 · Modified 1 Oct 2026

Description

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

References

What to do
  1. Check whether Connect Secure is in your asset inventory.
  2. Exploitation confirmed — patch within 72 hours.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2023-46805