Ivanti Connect Secure Zero-Day Chain
First seen Jul 3, 2026 · Updated Jul 3, 2026 · CVSS 9.1
Two chained zero-days in Ivanti VPN appliances enabling unauthenticated remote code execution. Mass exploitation targeting government and defense across 12 countries.
Affected Systems
Ivanti Connect Secure pre-22.7R2.5, Policy Secure, Neurons for ZTA
Indicators of Compromise
- Web shells in /dana-na/auth/
- Modified /home/perl/DSLogConfig.pm
- Integrity checker bypass
Remediation Steps
- 1
Patch or Disconnect
Apply Ivanti patches immediately or disconnect appliances
- 2
Run Integrity Check
Compare against known-good baselines
- 3
Factory Reset
Reset before patching if compromise found
- 4
Rotate VPN Credentials
Rotate all credentials that transited the VPN
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.