CISA Known Exploited Vulnerability

CVE-2025-22457 Ransomware

Ivanti · Connect Secure, Policy Secure, and ZTA Gateways

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Date added
BOD 22-01 due date
CWE CWE-121
Ransomware Known

CISA description

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

Required action

Apply mitigations as set forth in the CISA instructions linked below.

Notes & references