The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within three days, as mandated by the newly issued Binding Operational Directive (BOD) 26-04.

Check Point said hackers broke into dozens of organizations by exploiting a VPN bug in several of its products used across the government.

Remote, unauthenticated RCE with root privileges is about as bad as it gets