CiberLATAMbywhalemate

Chile Flags Critical Ivanti Flaws

Chile’s CSIRT warned of critical Ivanti and Citrix flaws with active exploitation, and urged patching, config review, and log monitoring.

Whalemate Labs · AI-assisted researchPublished:2 min read

Chile’s government CSIRT issued alerts about critical vulnerabilities in Ivanti products and Citrix NetScaler ADC and Gateway, with active exploitation confirmed in targeted campaigns against those devices. In both cases, the agency urged patching, configuration review, and log monitoring to spot possible compromises.

The Chilean government CSIRT on July 23, 2026, issued a security alert covering multiple critical vulnerabilities in Ivanti products, including CVE-2023-46805, CVE-2024-21887, CVE-2024-22024, CVE-2024-22026, CVE-2024-22028, CVE-2024-22029, and CVE-2024-22030. The agency said several of them have been actively exploited in campaigns aimed at Ivanti Connect Secure devices and other products in the vendor's lineup.

Ivanti Connect Secure under active exploitation

In that same alert, the CSIRT said CVE-2023-46805 and CVE-2024-21887 were chained together to compromise Ivanti Connect Secure devices. According to the notice, Ivanti confirmed active exploitation of those vulnerabilities by malicious actors.

The official guidance was to apply the vendor's patches and updates immediately, review device configurations, and monitor activity logs. If compromise is suspected, the CSIRT asked organizations to follow Ivanti's remediation guidance for the affected CVEs.

Citrix NetScaler ADC and Gateway

A week earlier, on July 17, 2026, the CSIRT had issued another security alert about critical vulnerabilities in Citrix NetScaler ADC and Gateway. In that case, it highlighted CVE-2023-4966, an information disclosure flaw that has been actively exploited in attacks against these appliances.

The agency stressed that CVE-2023-4966 has been used in active exploitation campaigns and recommended updating to fixed versions, restricting access to administrative interfaces, and reviewing connection logs to detect possible compromises.

Impact on Chilean infrastructure

The two alerts add to a series of recent warnings from Chile's government CSIRT about remote access and perimeter products exposed to active exploitation. The available material also includes an alert about vulnerabilities in Palo Alto Networks PAN-OS, although no technical details were provided for this report.

Sources

View all