logo

Zero-day exploits plague Ivanti Connect Secure appliances for second year running

ID: 6cfdcbfd-3066-56f0-82d1-b7bb17495991

STIX ID: report--6cfdcbfd-3066-56f0-82d1-b7bb17495991

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-01-09

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Ivanti disclosed two stack-based buffer overflow vulnerabilities—CVE-2025-0282 (critical, exploited in the wild for unauthenticated RCE) and CVE-2025-0283 (high, local privilege escalation)—affecting Connect Secure, Policy Secure, and Neurons for ZTA gateways; Mandiant and other responders observed exploitation beginning in mid-December with malware families (Spawn, Dryhook, Phasejam) tied to UNC5337/UNC5221 and warned of likely opportunistic widespread exploitation, urging immediate patching and taking affected appliances offline where patches are delayed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.