Skip to main content
Ivanti CSA Exploit Chain: Auth Bypass + SQLi/Command Injection to Webshell operation cover
COMING SOONAdvanced

Ivanti CSA Exploit Chain: Auth Bypass + SQLi/Command Injection to Webshell

A suspected nation-state operator chained four Ivanti Cloud Services Appliance zero-days against an internet-facing appliance: an unauthenticated path-traversal auth bypass, command injection in the date/time and reporting handlers for root-level execution, PHP webshells for persistence, theft of the appliance administrator password and root SSH key, and a SQL-injection pivot to a backend SQL Server via xp_cmdshell. Reconstruct the full chain from SIEM, endpoint XDR, and perimeter firewall telemetry, and classify the key techniques.

1h 15m
8 tasks
150 points
Free

Launches in 5 days

Oct 6, 2026

Tuesday, October 6, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

SIEMXDRFirewallQuery

What you'll investigate

8 objectives unlock when this operation goes live.

1Incident brief
2Find the unauthenticated entry point
3Recover the planted webshell
4Classify how the attacker code first ran
5Recover the compromised appliance credential
6Isolate the command-and-control egress
7Trace the pivot to the database host
8Recover the rootkit indicator

Be first when it launches

Create your free account now. The moment this operation goes live on Oct 6, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free