logo

Ivanti VPNs at Risk

ID: 8b2bfae8-d84b-54ff-887a-2c423456d4aa

STIX ID: report--8b2bfae8-d84b-54ff-887a-2c423456d4aa

Feed Name: Canary Trap

Threat Score
85/100

Date Published: 2025-04-14

Date Updated: 2026-05-13

Author: Canary Trap

...
...

A critical stack-based buffer overflow (CVE-2025-22457) in Ivanti Connect Secure VPN is being actively exploited by China-linked actors, placing over 5,100 VPN instances at risk of remote code execution; many systems remain unpatched, Pulse Connect Secure 9.x is end-of-support, and CISA has added the flaw to its known exploited vulnerabilities catalog.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.