U.S. CISA adds Ivanti Connect Secure, Policy Secure and ZTA Gateways flaw to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-22457 | Unauthenticated Stack Buffer Overflow RCE in Ivanti Connect Secure Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow (CWE-121) that can be triggered by a remote, unauthenticated attacker sending crafted input that overruns a fixed-size stack buffer on the affected gateway. Successful exploitation yields remote code execution on the appliance, giving an attacker control of an enterprise VPN or zero-trust access gateway and a foothold in the surrounding network. Any organization running the affected Ivanti gateway products is exposed, with impact concentrated among enterprises using these appliances for remote-access VPN and zero-trust network access. The vulnerability was added to CISA's KEV catalog on 2025-04-04 with known ransomware use, and its maximum EPSS score (100.0%, 100th percentile) signals near-certain exploitation pressure within 30 days. No public proof-of-concept is known, but confirmed in-the-wild exploitation makes this an actively abused, high-priority flaw. Do: Apply the mitigations required by CISA and update Connect Secure, Policy Secure, and ZTA Gateways to the patched releases designated in Ivanti's advisory, prioritizing internet-exposed VPN gateways. Given known ransomware use, review appliance and downstream logs for signs of compromise, and treat unpatched gateways as high risk given the 100th-percentile EPSS score. | 9.8 | 100% | KEV ransomware |
| largetens of thousands of deployed gateways, with on the order of 10k-100k internet-exposed appliances |
Full article572 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ivanti Connect Secure, Policy Secure and ZTA Gateways flaw to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apache Tomcat path equivalence vulnerability, tracked as CVE-2025-22457, to its Known Exploited Vulnerabilities (KEV) catalog.
The vulnerability CVE-2025-22457 is a stack-based buffer overflow that allows remote unauthenticated remote code execution.
Early this month, Ivanti released security updates to address a critical Connect Secure remote code execution vulnerability tracked as CVE-2025-22457. The vulnerability has been exploited by a China-linked threat actor since at least mid-March 2025.
Ivanti did not disclose details about the attack, however cybersecurity experts at Mandiant and Google Threat Intelligence Group (GTIG) linked the exploration attempts to an alleged China-linked cyberespionage group tracked as UNC5221.
The flaw impacts Ivanti Connect Secure (version 22.7R2.5 and earlier), Pulse Connect Secure 9.x (end-of-support as of December 31, 2024), Ivanti Policy Secure and ZTA gateways. The software company addressed the vulnerability with the release of Connect Secure 22.7R2.6 (released February 11, 2025).
“We are aware of a limited number of customers whose Ivanti Connect Secure (22.7R2.5 and earlier) and End-of-Support Pulse Connect Secure 9.1x appliances have been exploited at the time of disclosure.” reads the advisory published by the company. “The vulnerability is a buffer overflow with characters limited to periods and numbers, it was evaluated and determined not to be exploitable as remote code execution and didn’t meet the requirements of denial of service. However, Ivanti and our security partners have now learned the vulnerability is exploitable through sophisticated means and have identified evidence of active exploitation in the wild. We encourage all customers to ensure they are running Ivanti Connect Secure 22.7R2.6 as soon as possible, which remediates the vulnerability.”
Ivanti will release security patches for ZTA and Policy Secure gateways on April 19 and 21. No exploits are known yet, but admins should monitor ICT logs and reset compromised devices.
Ivanti urges admins to monitor Integrity Checker Tool (ICT) for web server crashes and reset compromised devices before redeploying them with version 22.7R2.6.
According to Google GTIG, threat actor UNC5221 exploited the flaw since March 2025 to deploy TRAILBLAZE and BRUSHFIRE malware, along with SPAWN malware.
The earliest evidence of observed CVE-2025-22457 exploitation occurred in mid-March 2025. Following successful exploitation, we observed the deployment of two newly identified malware families, the TRAILBLAZE in-memory only dropper and the BRUSHFIRE passive backdoor. Additionally, deployment of the previously reported SPAWN ecosystem of malware attributed to UNC5221 was also observed. UNC5221 is a suspected China-nexus espionage actor that we previously observed conducting zero-day exploitation of edge devices dating back to 2023.
“Following successful exploitation, we observed the deployment of two newly identified malware families, the TRAILBLAZE in-memory only dropper and the BRUSHFIRE passive backdoor,” reads the Google’s report.. “Additionally, deployment of the previously reported SPAWN ecosystem of malware attributed to UNC5221 was also observed.”
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by April 11, 2025.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/176332/security/u-s-cisa-adds-ivanti-connect-secure-policy-secure-and-zta-gateways-flaw-to-its-known-exploited-vulnerabilities-catalog-2.html