Loading
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Use CWE-77, Ivanti vendor hub and Connect Secure product page to widen CVE-2024-21887 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-55145, CVE-2025-55147 and CVE-2025-55142 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 27th, 2026.