logo

Ivanti Connect Secure RCE Vulnerability Actively Exploited in the Wild – Apply Patch Now!

ID: c24bdf34-92b0-5367-bb28-10748ff31e44

STIX ID: report--c24bdf34-92b0-5367-bb28-10748ff31e44

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-04-04

Date Updated: 2026-04-21

Author: Balaji N

...
...

**Ivanti CVE-2025-22457 executive summary:** Ivanti disclosed a CVSS 9.0 stack-based buffer overflow (CVE-2025-22457) in Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy Secure, and ZTA Gateways that allows unauthenticated RCE and has been actively exploited since mid-March 2025 by UNC5221 to deploy malware (Trailblaze, Brushfire, Spawn) and perform log tampering; Ivanti released patches for supported versions and recommends immediate patching, ICT monitoring, factory reset if compromised, and limiting internet exposure of affected appliances.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.