Ivanti has issued critical updates for its Cloud Services Appliance (CSA), addressing three zero-day vulnerabilities. These flaws, if exploited, could allow an attacker with administrative privileges to bypass security restrictions, execute arbitrary SQL commands, or achieve remote code execution (RCE). Notably, the zero-day vulnerabilities are being actively weaponized alongside a previously patched flaw, CVE-2024-8963, which was fixed last month. Given their active exploitation in attacks, users are strongly advised to apply the patches immediately to mitigate potential threats.
