logo

Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild

ID: 2f4a5451-0c2a-5f0a-9d73-add856b90b39

STIX ID: report--2f4a5451-0c2a-5f0a-9d73-add856b90b39

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2025-04-04

Date Updated: 2026-04-22

Author: Balaji

...
...

Ivanti disclosed CVE-2025-22457, a CVSS 9.0 stack-based buffer overflow in Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy Secure and ZTA Gateways that has been actively exploited since mid‑March 2025 by suspected China-linked UNC5221 to achieve unauthenticated RCE; Ivanti released patches (Connect Secure 22.7R2.6 and subsequent platform updates), recommends factory reset and redeploy for compromised appliances, and Mandiant and others have published IOCs and detection guidance—organizations are urged to patch or migrate immediately, especially unsupported systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.