CISA and the FBI have alerted organizations that hackers are actively exploiting security vulnerabilities in Ivanti Cloud Service Appliances, despite the release of patches in September and October 2024 for several critical issues, including an admin authentication bypass and remote code execution flaws. These vulnerabilities, now listed in CISA's Known Exploited Vulnerabilities Catalog, have been used in zero-day attacks to gain access, execute remote code, and establish webshells in victim networks. Federal agencies are directed to secure their Ivanti appliances under Binding Operational Directive 22-01, and both agencies strongly advise network administrators to upgrade their systems to mitigate ongoing risks.