CISA orders emergency measures due to Ivanti vulnerabilities
CISA issued emergency directives for organisations using Ivanti Connect Secure and Ivanti Policy Secure in response to actively exploited vulnerabilities.

News summary
CISA issued emergency directives for organisations using Ivanti Connect Secure and Ivanti Policy Secure in response to actively exploited vulnerabilities. The alert detailed risks such as credential theft, webshells, persistence, and lateral movement.
VPN, firewalls, and perimeter equipment must be among the highest priority assets for patching. A vulnerability in remote access can invalidate many internal defences.
Source: CISA — 31 January 2024
What happened
CISA issued an emergency directive in January 2024 aimed at federal agencies using Ivanti Connect Secure and Ivanti Policy Secure, in response to vulnerabilities being actively exploited by attackers.
The alert described risks including credential theft, webshell installation, persistence on compromised systems and lateral movement to other parts of the network, and required disconnecting affected devices until mitigations or patches were applied.
What it means for a mid-sized business
Remote access devices such as VPNs and gateways are an especially attractive entry point because they are designed to be reachable from outside the network. A vulnerability in them can bypass much of an organisation's internal defences.
The fact that the directive came from a public agency underlines its severity: this was not a general recommendation but an order for immediate disconnection until security could be assured.
What to review
When critical vulnerabilities affect remote-access devices, it's worth checking:
- Which VPN, firewall or remote-access devices the business runs and on what firmware version.
- Whether there is a procedure to temporarily disconnect a perimeter device without leaving users without access.
- Whether the vendor's security advisories for these devices are reviewed regularly.
- Whether, after a critical vulnerability, signs of compromise are checked in addition to applying the patch.
Frequently Asked Questions
- Why did CISA order devices disconnected instead of just patching them?
- Because the vulnerabilities allowed persistent compromise; applying the patch alone did not guarantee removing access an attacker might already have gained.
- Did this only affect US public agencies?
- The directive was mandatory for federal agencies, but the vulnerabilities affected any organisation using the same products, in any country.
- How should a business respond to a similar advisory?
- By immediately applying the vendor's mitigations, checking for signs of compromise and, if necessary, disconnecting the device until it is confirmed safe to bring back online.
Concepts mentioned in this article: Firewall · Vulnerability
Technology only adds value when it is properly designed, protected, and maintained. Seintec can help you implement these best practices in your company; speak to our team to assess your environment.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.