Ivanti.Connect.Secure.saml-sso.XXE

description-logoDescription

This indicates an attack attempt to exploit an External Entity Injection Vulnerability in Ivanti Connect Secure, Ivanti Policy Secure and ZTA Gateways.
A remote authenticated attacker could exploit this vulnerability by sending malicious XML data to the target server. Successful exploitation could result in arbitrary code within the context of the application.

description-logoOutbreak Alert

Widespread exploitation of zero-day vulnerabilities affecting Ivanti Connect Secure and Policy Secure gateways underway.

View the full Outbreak Alert Report

affected-products-logoAffected Products

Ivanti Connect Secure versions 9.1R14.4, 9.1R17.2, 9.1R18.3, 22.4R2.2, 22.5R1.1, and 22.5R2.2
Ivanti Policy Secure version 22.5R1.1
Ivanti ZTA version 22.6R1.3

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2026-02-05 35.164
Modified
Sig Added
2026-01-12 35.148
Modified
Sig Added
2024-10-29 28.892
New
2024-10-17 28.885
Removed
2024-03-13 27.748
Modified
Default_action:pass:drop
2024-03-04 27.742
New