<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Ivanti</title><description>Cybersecurity articles tagged #Ivanti on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Ivanti&apos;s LLM Automation for Vulnerability Remediation</title><link>https://runtimerebel.com/blog/ivanti-s-llm-automation-for-vulnerability-remediation</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-s-llm-automation-for-vulnerability-remediation</guid><description>Ivanti explores using Large Language Models (LLMs) for automated vulnerability remediation, showing early effectiveness but raising questions about cost and human…</description><pubDate>Mon, 20 Jul 2026 21:14:12 GMT</pubDate><category>LLMs</category><category>AI</category><category>Automation</category><category>Vulnerability Management</category><category>Ivanti</category><category>Cybersecurity Operations</category></item><item><title>FortiSandbox Command Injection (CVE-2026-25089) &amp; Critical Vendor Patches</title><link>https://runtimerebel.com/blog/fortisandbox-command-injection-cve-2026-25089-critical-vendor-patches</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortisandbox-command-injection-cve-2026-25089-critical-vendor-patches</guid><description>Critical patches from Fortinet, Ivanti, and SAP address vulnerabilities including CVE-2026-25089 (FortiSandbox command injection), enabling RCE and info disclosure.</description><pubDate>Wed, 10 Jun 2026 17:14:48 GMT</pubDate><category>CVE-2026-25089</category><category>FortiSandbox</category><category>Fortinet</category><category>Ivanti</category><category>SAP</category><category>Command Injection</category><category>RCE</category><category>Vulnerability Management</category></item><item><title>Ivanti, Fortinet, and n8n Disclose Critical RCE and Auth Bypass Flaws</title><link>https://runtimerebel.com/blog/ivanti-fortinet-and-n8n-disclose-critical-rce-and-auth-bypass-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-fortinet-and-n8n-disclose-critical-rce-and-auth-bypass-flaws</guid><description>Ivanti, Fortinet, n8n, and SAP release urgent security patches for critical vulnerabilities including CVE-2026-5444 and CVE-2026-8043. Update systems now.</description><pubDate>Mon, 18 May 2026 13:23:34 GMT</pubDate><category>CVE-2026-8043</category><category>CVE-2026-5444</category><category>Ivanti</category><category>Fortinet</category><category>N8n</category><category>RCE</category></item><item><title>Ivanti EPMM CVE-2023-35078 Zero-Day: Urgent CISA Patch Directive</title><link>https://runtimerebel.com/blog/ivanti-epmm-cve-2023-35078-zero-day-urgent-cisa-patch-directive</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-epmm-cve-2023-35078-zero-day-urgent-cisa-patch-directive</guid><description>CISA orders federal agencies to patch Ivanti EPMM CVE-2023-35078 within four days following active zero-day exploitation against government networks.</description><pubDate>Fri, 08 May 2026 12:37:44 GMT</pubDate><category>CVE-2023-35078</category><category>Ivanti</category><category>CISA KEV</category><category>Endpoint Manager Mobile</category><category>Zero-Day</category></item><item><title>CVE-2026-6973: Ivanti EPMM Exploited in the Wild — Patch Guidance</title><link>https://runtimerebel.com/blog/cve-2026-6973-ivanti-epmm-exploited-in-the-wild-patch-guidance</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-6973-ivanti-epmm-exploited-in-the-wild-patch-guidance</guid><description>CISA adds CVE-2026-6973, an improper input validation vulnerability in Ivanti Endpoint Manager Mobile, to the KEV catalog following active exploitation.</description><pubDate>Thu, 07 May 2026 16:44:28 GMT</pubDate><category>CVE-2026-6973</category><category>Ivanti</category><category>EPMM</category><category>CISA KEV</category></item><item><title>CVE-2023-35081: Ivanti EPMM Remote Code Execution Zero-Day Analysis</title><link>https://runtimerebel.com/blog/cve-2023-35081-ivanti-epmm-remote-code-execution-zero-day-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2023-35081-ivanti-epmm-remote-code-execution-zero-day-analysis</guid><description>Ivanti warns of a high-severity RCE vulnerability in EPMM exploited in zero-day attacks. Secure your systems by patching CVE-2023-35081 today.</description><pubDate>Thu, 07 May 2026 16:41:21 GMT</pubDate><category>CVE-2023-35081</category><category>Ivanti</category><category>EPMM</category><category>RCE</category><category>Zero-Day</category></item><item><title>Ivanti EPMM RCE via CVE-2025-22514: Technical Analysis and Patching</title><link>https://runtimerebel.com/blog/ivanti-epmm-rce-via-cve-2025-22514-technical-analysis-and-patching</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-epmm-rce-via-cve-2025-22514-technical-analysis-and-patching</guid><description>Critical security alert for Ivanti EPMM: CVE-2025-22514 and CVE-2025-22515 allow remote command injection and file uploads. Patch to version 12.1.0.1 immediately.</description><pubDate>Fri, 24 Apr 2026 08:52:03 GMT</pubDate><category>Ivanti</category><category>CVE-2025-22514</category><category>CVE-2025-22515</category><category>EPMM</category><category>RCE</category></item><item><title>CISA KEV Expansion: Exploit Guidance for Cisco, Kentico, and Zimbra</title><link>https://runtimerebel.com/blog/cisa-kev-expansion-exploit-guidance-for-cisco-kentico-and-zimbra</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-kev-expansion-exploit-guidance-for-cisco-kentico-and-zimbra</guid><description>CISA adds 8 vulnerabilities to the KEV catalog, including critical flaws in Cisco ASA and Zimbra. Analyze technical impact and remediation requirements.</description><pubDate>Tue, 21 Apr 2026 12:33:32 GMT</pubDate><category>CVE-2024-20481</category><category>CVE-2024-45519</category><category>CVE-2024-29847</category><category>Cisco</category><category>Zimbra</category><category>Ivanti</category></item><item><title>Ivanti Neurons for ITSM Patches CVE-2024-45504 and CVE-2024-45505</title><link>https://runtimerebel.com/blog/ivanti-neurons-for-itsm-patches-cve-2024-45504-and-cve-2024-45505</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-neurons-for-itsm-patches-cve-2024-45504-and-cve-2024-45505</guid><description>Ivanti addresses two high-severity flaws in Neurons for ITSM, CVE-2024-45504 and CVE-2024-45505, preventing session persistence and cross-user data exposure.</description><pubDate>Wed, 15 Apr 2026 12:31:03 GMT</pubDate><category>Ivanti</category><category>ITSM</category><category>CVE-2024-45504</category><category>CVE-2024-45505</category><category>Authentication Bypass</category><category>Access Control</category></item><item><title>CVE-2024-21762 and Ivanti Flaws: Edge Gateway Scanning Escalates</title><link>https://runtimerebel.com/blog/cve-2024-21762-and-ivanti-flaws-edge-gateway-scanning-escalates</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-21762-and-ivanti-flaws-edge-gateway-scanning-escalates</guid><description>Technical analysis of ongoing scanning activity targeting Ivanti and Fortinet SSL-VPN gateways. Learn to detect exploits and apply critical mitigations.</description><pubDate>Wed, 15 Apr 2026 08:41:41 GMT</pubDate><category>Ivanti</category><category>Fortinet</category><category>Ssl Vpn</category><category>CVE-2024-21762</category><category>CVE-2023-46805</category><category>RCE</category></item><item><title>Ivanti CSA 4.6 Exploited via CVE-2024-9380: Migration Required</title><link>https://runtimerebel.com/blog/ivanti-csa-4-6-exploited-via-cve-2024-9380-migration-required</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-csa-4-6-exploited-via-cve-2024-9380-migration-required</guid><description>Attackers are actively exploiting Ivanti CSA 4.6 via CVE-2024-9379 and CVE-2024-9380. Learn how to detect these command injection exploits and migrate to version 5.0.</description><pubDate>Wed, 08 Apr 2026 08:35:31 GMT</pubDate><category>Ivanti</category><category>CVE-2024-9379</category><category>CVE-2024-9380</category><category>Command Injection</category><category>Exploitation</category></item><item><title>CVE-2024-29847: Ivanti Endpoint Manager RCE Patch and Detection Guide</title><link>https://runtimerebel.com/blog/cve-2024-29847-ivanti-endpoint-manager-rce-patch-and-detection-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-29847-ivanti-endpoint-manager-rce-patch-and-detection-guide</guid><description>Ivanti Endpoint Manager (EPM) critical RCE (CVE-2024-29847) allows unauthenticated attackers to execute code with SYSTEM privileges via deserialization.</description><pubDate>Tue, 07 Apr 2026 04:52:50 GMT</pubDate><category>CVE-2024-29847</category><category>Ivanti</category><category>Endpoint Manager</category><category>RCE</category><category>Patch Management</category></item><item><title>Ivanti Connect Secure RCE: Internal Network Vulnerability Detection</title><link>https://runtimerebel.com/blog/ivanti-connect-secure-rce-internal-network-vulnerability-detection</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-connect-secure-rce-internal-network-vulnerability-detection</guid><description>Analyze the impact of Ivanti Connect Secure vulnerabilities and learn how to conduct internal network vulnerability scanning for Ivanti appliances to detect flaws.</description><pubDate>Fri, 03 Apr 2026 08:29:48 GMT</pubDate><category>Ivanti</category><category>CVE-2023-46805</category><category>CVE-2024-21887</category><category>ICS</category><category>RCE</category></item><item><title>Ivanti Connect Secure RCE via CVE-2024-21887 — Mitigation Guide</title><link>https://runtimerebel.com/blog/ivanti-connect-secure-rce-via-cve-2024-21887-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-connect-secure-rce-via-cve-2024-21887-mitigation-guide</guid><description>Critical Ivanti Connect Secure vulnerabilities CVE-2023-46805 and CVE-2024-21887 continue to be exploited. Learn detection strategies and mitigation steps.</description><pubDate>Thu, 02 Apr 2026 08:34:23 GMT</pubDate><category>CVE-2024-21887</category><category>CVE-2023-46805</category><category>Ivanti</category><category>RCE</category><category>Authentication Bypass</category></item><item><title>Ivanti Connect Secure RCE via CVE-2025-0551 — Mitigation Guide</title><link>https://runtimerebel.com/blog/ivanti-connect-secure-rce-via-cve-2025-0551-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-connect-secure-rce-via-cve-2025-0551-mitigation-guide</guid><description>Unauthenticated RCE vulnerabilities CVE-2025-0551 and CVE-2025-0552 impact Ivanti Connect Secure gateways. Learn how to detect and patch these critical flaws.</description><pubDate>Thu, 19 Mar 2026 04:43:34 GMT</pubDate><category>CVE-2025-0551</category><category>CVE-2025-0552</category><category>Ivanti</category><category>Connect Secure</category><category>RCE</category></item><item><title>Ivanti vTM Authentication Bypass: CVE-2024-7593 Mitigation Guide</title><link>https://runtimerebel.com/blog/ivanti-vtm-authentication-bypass-cve-2024-7593-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-vtm-authentication-bypass-cve-2024-7593-mitigation-guide</guid><description>Ivanti patches a critical authentication bypass in Virtual Traffic Manager. Learn how CVE-2024-7593 allows unauthenticated administrative access.</description><pubDate>Wed, 18 Mar 2026 12:25:10 GMT</pubDate><category>CVE-2024-7593</category><category>Ivanti</category><category>Authentication Bypass</category><category>vTM</category></item><item><title>Fortinet, Ivanti, and Intel Patch High-Severity RCE Vulnerabilities</title><link>https://runtimerebel.com/blog/fortinet-ivanti-and-intel-patch-high-severity-rce-vulnerabilities</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortinet-ivanti-and-intel-patch-high-severity-rce-vulnerabilities</guid><description>Fortinet, Ivanti, and Intel have issued patches for high-severity vulnerabilities in FortiClient, ICS gateways, and various hardware drivers.</description><pubDate>Wed, 11 Mar 2026 12:20:19 GMT</pubDate><category>CVE-2024-36513</category><category>CVE-2024-37375</category><category>Fortinet</category><category>Ivanti</category><category>Intel</category><category>RCE</category></item><item><title>Ivanti EPM CVE-2024-29824 Exploited: Technical Analysis and Patching</title><link>https://runtimerebel.com/blog/ivanti-epm-cve-2024-29824-exploited-technical-analysis-and-patching</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-epm-cve-2024-29824-exploited-technical-analysis-and-patching</guid><description>CISA warns of active exploitation of CVE-2024-29824 in Ivanti Endpoint Manager. Secure your Core server with our technical analysis and mitigation guide.</description><pubDate>Tue, 10 Mar 2026 12:19:43 GMT</pubDate><category>CVE-2024-29824</category><category>Ivanti</category><category>Endpoint Manager</category><category>CISA KEV</category><category>RCE</category><category>SQL Injection</category></item><item><title>CVE-2024-29847: Ivanti EPM RCE Under Active Exploitation - Patch Now</title><link>https://runtimerebel.com/blog/cve-2024-29847-ivanti-epm-rce-under-active-exploitation-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-29847-ivanti-epm-rce-under-active-exploitation-patch-now</guid><description>CISA warns of active exploitation of a critical Ivanti EPM vulnerability (CVE-2024-29847). Learn how to mitigate this unauthenticated RCE threat immediately.</description><pubDate>Tue, 10 Mar 2026 12:18:34 GMT</pubDate><category>Ivanti</category><category>CVE-2024-29847</category><category>RCE</category><category>CISA KEV</category><category>Endpoint Management</category></item><item><title>CISA Flags SolarWinds, Ivanti, and Workspace One Flaws in KEV Update</title><link>https://runtimerebel.com/blog/cisa-flags-solarwinds-ivanti-and-workspace-one-flaws-in-kev-update</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-flags-solarwinds-ivanti-and-workspace-one-flaws-in-kev-update</guid><description>CISA adds vulnerabilities in SolarWinds, Ivanti, and Omnissa Workspace One UEM to its Known Exploited Vulnerabilities catalog following active exploitation.</description><pubDate>Tue, 10 Mar 2026 08:17:06 GMT</pubDate><category>CVE-2021-22054</category><category>CISA KEV</category><category>Omnissa</category><category>SolarWinds</category><category>Ivanti</category></item><item><title>CVE-2026-1603: CISA Warns of Active Ivanti and SolarWinds Exploitation</title><link>https://runtimerebel.com/blog/cve-2026-1603-cisa-warns-of-active-ivanti-and-solarwinds-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-1603-cisa-warns-of-active-ivanti-and-solarwinds-exploitation</guid><description>CISA adds CVE-2026-1603, CVE-2025-26399, and CVE-2021-22054 to the KEV catalog, requiring immediate remediation for Ivanti, SolarWinds, and Omnissa systems.</description><pubDate>Mon, 09 Mar 2026 20:13:15 GMT</pubDate><category>CVE-2026-1603</category><category>CVE-2025-26399</category><category>CVE-2021-22054</category><category>Ivanti</category><category>SolarWinds</category><category>Omnissa</category><category>CISA KEV</category></item><item><title>CVE-2025-0282: Ivanti Connect Secure Heap Overflow — Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2025-0282-ivanti-connect-secure-heap-overflow-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-0282-ivanti-connect-secure-heap-overflow-mitigation-guide</guid><description>Technical analysis of the Ivanti Connect Secure heap overflow (CVE-2025-0282) allowing unauthenticated RCE. Includes detection steps and patch guidance.</description><pubDate>Wed, 04 Mar 2026 04:37:49 GMT</pubDate><category>CVE-2025-0282</category><category>Ivanti</category><category>Connect Secure</category><category>Remote Code Execution</category><category>Heap Overflow</category></item><item><title>CVE-2025-24036: Critical RCE in Ivanti Connect Secure — Patch Now</title><link>https://runtimerebel.com/blog/cve-2025-24036-critical-rce-in-ivanti-connect-secure-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-24036-critical-rce-in-ivanti-connect-secure-patch-now</guid><description>Exploit analysis of CVE-2025-24036 in Ivanti Connect Secure and Policy Secure. Learn to detect unauthenticated RCE attempts and apply mitigation strategies.</description><pubDate>Mon, 02 Mar 2026 03:15:14 GMT</pubDate><category>CVE-2025-24036</category><category>Ivanti</category><category>RCE</category><category>Network Security</category><category>Volt Typhoon</category></item><item><title>CISA Warns of RESURGE Malware Persistence on Ivanti Devices</title><link>https://runtimerebel.com/blog/cisa-warns-of-resurge-malware-persistence-on-ivanti-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-warns-of-resurge-malware-persistence-on-ivanti-devices</guid><description>CISA details RESURGE, a sophisticated implant exploiting CVE-2025-0282 in Ivanti Connect Secure, capable of remaining dormant to bypass detection and recovery.</description><pubDate>Fri, 27 Feb 2026 16:15:43 GMT</pubDate><category>RESURGE</category><category>Ivanti</category><category>CVE-2025-0282</category><category>CISA</category><category>Connect Secure</category><category>Threat Intelligence</category></item></channel></rss>