Ivanti Fully Patched Connect Secure RCE Vulnerability That Actively Exploited in the Wild
ID: 2f4a5451-0c2a-5f0a-9d73-add856b90b39
STIX ID: report--2f4a5451-0c2a-5f0a-9d73-add856b90b39
Feed Name: GBHackers
Ivanti disclosed CVE-2025-22457, a CVSS 9.0 stack-based buffer overflow in Ivanti Connect Secure, Pulse Connect Secure, Ivanti Policy Secure and ZTA Gateways that has been actively exploited since mid‑March 2025 by suspected China-linked UNC5221 to achieve unauthenticated RCE; Ivanti released patches (Connect Secure 22.7R2.6 and subsequent platform updates), recommends factory reset and redeploy for compromised appliances, and Mandiant and others have published IOCs and detection guidance—organizations are urged to patch or migrate immediately, especially unsupported systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
