logo

CVE-2025-0282 and CVE-2025-0283: Critical Ivanti 0days Exploited in the Wild

ID: 5c0591b2-dca1-5d01-8db5-6212a2e12efa

STIX ID: report--5c0591b2-dca1-5d01-8db5-6212a2e12efa

Feed Name: Wiz Blog

Threat Score
88/100

Date Published: 2025-01-09

Date Updated: 2026-05-01

...
...

Ivanti has confirmed active exploitation of CVE-2025-0282 (an unauthenticated RCE zero-day) and CVE-2025-0283 in Ivanti Connect Secure appliances; Mandiant observed exploitation since December 2024 with multiple malware families and IOCs (including DRYHOOK and PHASEJAM) and some activity attributed to the China-nexus cluster UNC5337. The report details attacker reconnaissance and post-exploitation behaviors (web shells, disabling SELinux, tunneling, credential theft, log tampering), lists affected products and file-based IOCs, and urges customers to upgrade appliances, use Ivanti's ICT, and perform factory reset/reinstall if compromise is detected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.