logo

CISA Adds Actively Exploits Ivanti Connect Secure Vulnerability in Known Exploited Catalog

ID: b77d9e42-578c-5513-8129-8fe82b274766

STIX ID: report--b77d9e42-578c-5513-8129-8fe82b274766

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-04-04

Date Updated: 2026-04-21

Author: Balaji N

...
...

CVE-2025-22457 is a critical (CVSS 9.0) stack-based buffer overflow in Ivanti Connect Secure, Policy Secure, and ZTA Gateways that has been actively exploited since mid-March 2025; CISA added it to the Known Exploited Vulnerabilities catalog and attributes activity to UNC5221, which has deployed malware such as Trailblaze and Brushfire. The report details affected versions, patch availability/timelines, recommended detection and remediation steps (Ivanti ICT, factory resets, credential rotation, forensic imaging, and isolation), and urges immediate patching and incident response for suspected compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.