The Cybersecurity and Infrastructure Security Agency on Monday gave federal civilian agencies until Friday, Sept. 26, to patch or disconnect internet-facing Ivanti Connect Secure VPN appliances against a newly cataloged zero-day that attackers are already chaining to reach agency networks, according to an alert posted to CISA’s Known Exploited Vulnerabilities list and a binding operational directive notice reviewed by agency chief information security officers.

What is being exploited

CISA assigned the flaw CVE-2026-21488, an authentication bypass in certain Connect Secure builds that lets remote actors obtain privileged sessions without valid credentials. Ivanti published emergency builds Sunday night; CISA confirmed “mass exploitation activity” against U.S. government and contractor VPN gateways over the weekend. The vulnerability is distinct from earlier Endpoint Manager and Sentry issues that filled KEV deadlines earlier in the year, but it follows the same pattern: edge VPN software with broad trust inside agency perimeters.

National Institute of Standards and Technology metadata lists the issue at CVSS 9.1, with network attack complexity rated low. Security researchers monitoring sinkholes said they observed follow-on attempts to dump Active Directory credentials within minutes of initial compromise—behavior consistent with ransomware affiliates and espionage crews that have targeted Ivanti stacks since 2024.

What agencies must do by Friday

Under Binding Operational Directive 22-01, Federal Civilian Executive Branch agencies must remediate KEV entries by the published due date or document an approved exception. For CVE-2026-21488, CISA’s required action is blunt: apply vendor patches per Ivanti’s bulletin, restrict management interfaces to out-of-band networks, or remove affected appliances from production. Agencies that cannot patch must submit compensating controls to CISA and the Office of Management and Budget by 11:59 p.m. Eastern on Sept. 26.

Several large departments began maintenance windows Sunday after CISA’s pre-release coordination call, according to two CISOs who spoke on condition they not be named discussing active incidents. One cabinet agency said it took a subset of diplomatic VPN concentrators offline entirely rather than risk weekend exposure while testing Ivanti’s fix across geographically distributed appliances.

Why VPN deadlines keep shrinking

CISA has repeatedly compressed remediation windows for perimeter gear after threat actors weaponized patches within hours. A three-day directive issued this summer for another vendor’s VPN flaw became the template for the Ivanti order, officials said. The agency’s message to FCEB shops is that internet-facing remote access is now treated like critical infrastructure during active campaigns—not a ticket that can wait for the next monthly patch cycle.

Private-sector operators are not legally bound by BOD 22-01, but CISA urged all Connect Secure customers to assume compromise if they have not applied the Sunday builds. Ivanti’s advisory lists affected versions and provides indicators of compromise, including unexpected admin accounts and unfamiliar cron jobs on appliances.

What remains exposed

Even patched gateways can leave residual risk if attackers already established persistence inside Windows or Linux hosts reachable from VPN subnets. CISA’s emergency guidance tells agencies to hunt for lateral movement using the same credential-dumping tools seen in prior Ivanti waves, and to rotate secrets for service accounts reachable from VPN address space.

For federal security teams, the weekend’s exploitation is a repeat exam on a familiar subject: VPN appliances remain the soft outer shell of many .gov networks. Friday’s deadline does not end the incident— it only ends the grace period for leaving that shell unlatched.

State and local governments that purchased surplus federal VPN hardware should treat Monday’s bulletin as binding guidance even without a legal mandate, CISA officials said on a call with critical-infrastructure partners. Several university hospital systems running Connect Secure for clinician remote access said they would mirror the federal patch window to avoid becoming a bridge into research networks that hold sensitive trial data.

Ivanti’s incident-response hotline reported call volume at twice normal levels Sunday night as agencies verified build numbers on appliances that had not checked in to centralized management for months—a common gap in smaller field offices that now carries national-security weight.