app.cubelet.ai← cubelet.ai
GRID42INTELLIGENCE TRACKERAI governance · compliance · regulatory signals
← All digests

VulnOps

2026-09-21
Today · VULNOPS

CISA has added an Ivanti Connect Secure vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation in the wild. This addition triggers mandatory prioritization requirements for federal contractors and heightens urgency for all organizations running Ivanti Connect Secure products.

  • Ivanti Connect Secure vulnerability added to CISA KEV catalog: Organizations must immediately prioritize patching this vulnerability as KEV catalog inclusion indicates confirmed active exploitation and federal compliance obligations for covered entities.

Audit your environment today for Ivanti Connect Secure instances and initiate emergency patching workflows, particularly if you are a federal contractor or critical infrastructure operator subject to CISA directives.

Signals in this digest
CISA adds Ivanti Connect Secure vulnerability to KEV catalog

The critical vulnerability was initially fixed on Feb. 11 with the release of Ivanti Connect Secure (ICS) version 22.7R2.6. At the time, the software vendor had determined the flaw was exploitable in remote code execution attacks. "However, Ivanti and our security partners have now learned the vulnerability is exploitable through sophisticated means and have identified evidence of active exploitation in the wild," the company said in the advisory. [...] "Customers running ICS 9.X (end of life) a