
Ivanti CSA Exploit Chain: Auth Bypass + SQLi/Command Injection to Webshell
A suspected nation-state operator chained four Ivanti Cloud Services Appliance zero-days against an internet-facing appliance: an unauthenticated path-traversal auth bypass, command injection in the date/time and reporting handlers for root-level execution, PHP webshells for persistence, theft of the appliance administrator password and root SSH key, and a SQL-injection pivot to a backend SQL Server via xp_cmdshell. Reconstruct the full chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key techniques.
Launches in 5 days
Tuesday, October 6, 2026 at 9:00 AM
Be ready the moment it drops, free.
Training Tools
What you'll investigate
8 objectives unlock when this operation goes live.
Be first when it launches
Create your free account now. The moment this operation goes live on Oct 6, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.
Get Started Free