CVE-2024-22024: Ivanti Connect Secure

High severity, CVSS 8.3. EPSS: 94.7% chance of exploitation in the next 30 days.

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

Affected products

  • Ivanti Connect Secure: version 9.1 only; version 22.4 only; version 22.5 only
  • Ivanti Policy Secure: version 22.5 only
  • Ivanti Zero Trust Access Gateway: version 22.6 only

Published 2024-02-13. Last modified 2026-06-17.