CISA Adds Actively Exploits Ivanti Connect Secure Vulnerability in Known Exploited Catalog
ID: b77d9e42-578c-5513-8129-8fe82b274766
STIX ID: report--b77d9e42-578c-5513-8129-8fe82b274766
Feed Name: cybersecurityNews.com
CVE-2025-22457 is a critical (CVSS 9.0) stack-based buffer overflow in Ivanti Connect Secure, Policy Secure, and ZTA Gateways that has been actively exploited since mid-March 2025; CISA added it to the Known Exploited Vulnerabilities catalog and attributes activity to UNC5221, which has deployed malware such as Trailblaze and Brushfire. The report details affected versions, patch availability/timelines, recommended detection and remediation steps (Ivanti ICT, factory resets, credential rotation, forensic imaging, and isolation), and urges immediate patching and incident response for suspected compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
