Ivanti fixes three critical flaws in Connect Secure & Policy Secure
ID: b7fd378c-3981-5a7d-96ad-99c1dcf47926
STIX ID: report--b7fd378c-3981-5a7d-96ad-99c1dcf47926
Feed Name: Bleeping Computer
Ivanti released security updates for Ivanti Connect Secure (ICS), Ivanti Policy Secure (IPS), and Ivanti Secure Access Client (ISAC) to patch multiple vulnerabilities — most notably three critical CVEs (CVE-2025-22467, CVE-2024-38657, CVE-2024-10644) that can allow remote authenticated attackers to achieve code execution or arbitrary file writes; affected versions include ICS 22.7R2.5 and older, IPS 22.7R1.2 and older, and ISAC 22.7R4 and below, with fixes available in ICS 22.7R2.6, IPS 22.7R1.3, and ISAC 22.8R1; Ivanti reports no active exploitation but urges immediate patching and notes Pulse Connect Secure 9.x will not be patched due to end-of-support.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
