The US government identifies a major security breach in Ivanti, so patch now

The US Cybersecurity and Infrastructure Security Agency (CISA) has added a known Ivanti bug to its Known Exploited Vulnerabilities (KEV) catalog, indicating it is being actively exploited in the wild.

The newly added bug is a SQL Injection vulnerability, which was found this spring in the Core server of Ivanti Endpoint Manager (EPM) 2022 SU5 and older. It allows an unauthenticated attacker within the same network to execute arbitrary code. It is tracked as CVE-2024-29824 and has a severity score of 9.6 (critical).