Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Ivanti Cloud Services Appliance OS Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability has been identified in Ivanti Cloud Services Appliance (CSA) versions 4.6 Patch 518 and prior. This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary commands on the underlying operating system. Exploitation of this vulnerability could lead to unauthorized access and control over the affected system.

Impact

Successful exploitation allows an authenticated attacker with administrative privileges to execute commands on the operating system level, potentially leading to full system compromise.

Remediation

Users are advised to upgrade to Ivanti Cloud Services Appliance version 5.0, the only supported version that does not contain this vulnerability. For those on Ivanti CSA 4.6 Patch 518, an update to Patch 519 is available. However, as version 4.6 has reached end-of-life, the preferred option is to upgrade to version 5.0.

Added: May 15, 2026, 11:15 AM
Updated: May 15, 2026, 11:15 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
6.1
remediation
7.9
relevance
0.0
threat
9.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.