CVE-2024-20399 is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 2 intelligence report mentions.
CVE-2024-20399 is a vulnerability tracked across 3 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed November 10, 2025; most recent activity June 24, 2026.
Operation Highland, attributed to the Velvet Ant cyberespionage group, involved a sophisticated attack that began in 2016 and persisted undetected for a decade. The attackers hijacked the authentication stack of a major…
A critical vulnerability in Cisco's Identity Services Engine (ISE), tracked as CVE-2024-20399, allows unauthenticated remote attackers to trigger system restarts, leading to denial-of-service conditions. The flaw…
A critical denial-of-service vulnerability in Cisco's Identity Services Engine (ISE) has been identified, allowing unauthenticated attackers to crash the system. The flaw, tracked as CVE-2024-20399, affects ISE versions…
CVE-2024-20399 is a vulnerability tracked by ThreatCluster, appearing in 3 threat clusters built from 2 intelligence report mentions.
The most recent intelligence report mentioning CVE-2024-20399 on ThreatCluster is dated June 24, 2026. Activity was first observed November 10, 2025, giving a tracked span from then to June 24, 2026.
Across ThreatCluster reporting, CVE-2024-20399 most frequently co-occurs with DDoS, Malware, Operation Highland, China, CWE-287 - Improper Authentication, among 12 tracked related entities.
The most significant recent cluster is “Operation Highland: Velvet Ant's Decade-Long Espionage Campaign” (9 articles · Updated June 13, 2026). CVE-2024-20399 appears across 3 threat clusters in total, listed above with sources.
CVE-2024-20399 appears in 2 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.