CVE-2025-22457General(ivanti / connect_secure)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch ivanti connect_secure systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

7.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-04-11. Apply mitigations as set forth in the CISA instructions linked below.

Weakness type (CWE)
CWE-121CWE-787

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • connect_secure
  • policy_secure
  • zero_trust_access_gateway

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 4 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-21); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
connect_securepolicy_securezero_trust_access_gateway

2 versions affected across 3 products

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-04: 1Mentions · 2026-02-23: 1Mentions · 2026-04-21: 3Mentions · 2026-06-17: 1PoC Mentioned / Linked · 2026-02-23: 1Exploit Tool / Code · 2026-02-23: 1Active Exploitation · 2026-06-17: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-04: 1Technical Details · 2026-06-17: 102-0402-2304-2106-17
Signal classification4 categories
General
350.0%
Patch
116.7%
PoC
116.7%
Active Exploitation
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-041
Patch1
2026-02-231
PoC1
2026-04-213
General3
2026-06-171
Active Exploitation1
Full discourse6 posts
  • Цитатник пандочки🇷🇺@DutyFrutti
    PoC

    Почему CVE-2019-11510 и CVE-2025-22457 актуальны в 2026 1. Тысячи непропатченных устройств По данным апреля 2025 года — из ~12 500 публично доступных Ivanti/Pulse серверов 66% уязвимы. Половина из них на версии 9.x, которая патчей не получит никогда. 2. EOL не означает "выключили" Организации продолжают использовать устройства после окончания поддержки годами. VPN-шлюз стоит на периметре, "работает" — никто не трогает. 3. Публичные PoC в открытом доступе 4. Лакомая цель Контроль над VPN-шлюзом = доступ во внутреннюю сеть + учётные данные всех пользователей + возможность перехвата трафика. Максимальный результат при минимальных усилиях. poc: https://github.com/sfewer-r7/CVE-2025-22457 poc2: https://github.com/lions2012/Penetration_Testing_POC/tree/main/CVE-2019-11510

    Post summary

    The post emphasizes that CVE‑2019‑11510 and CVE‑2025‑22457 remain critical due to many unpatched Ivanti/Pulse VPN gateways and provides publicly available PoC code for exploitation.

    00011181
    27 followersView on X
  • ThreatCluster@threatcluster
    Active Exploitation

    China-linked UNC5221 exploited Ivanti Connect Secure CVE-2025-22457 unauthenticated remote code execution flaw against ICS 9.x and 22.7R2.5 and earlier, deploying TRAILBLAZE and BRUSHFIRE malware, Mandiant reported. https://threatcluster.io/cluster/critical-remote-code-execution-vulnerability-exploited-by-ch-436da75c

    Post summary

    The post confirms that the Chinese threat actor UNC5221 actively exploited the unauthenticated remote code execution vulnerability CVE‑2025‑22457 in Ivanti Connect Secure, deploying TRAILBLAZE and BRUSHFIRE malware in the wild.

    0000074
    356 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2025-22457 — Omegatech LTD Visit -- https://cti.loginsoft.com/ip/130.12.180.105 #Loginsoft #Cytellite #Cybersecurity #CVE202522457 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/guJGalElqL

    Post summary

    The tweet only states that Cytellite has recently detected activity related to CVE-2025-22457 without providing technical details, exploit information, or remediation advice.

    00000254
    20 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2025-22457 — Omegatech LTD Visit -- https://cti.loginsoft.com/ip/130.12.180.105 #Loginsoft #Cytellite #Cybersecurity #CVE202522457 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/wYSkUjbHNR

    Post summary

    The tweet reports the detection of CVE-2025-22457 by Cytellite but provides no additional technical, exploit, or mitigation details.

    00000280
    20 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2025-22457 — Omegatech LTD Visit -- https://cti.loginsoft.com/ip/130.12.180.105 #Loginsoft #Cytellite #Cybersecurity #CVE202522457 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/6HKIjYrKSf

    Post summary

    The tweet announces detection of CVE‑2025‑22457 by Cytellite and directs readers to a CTI URL, but provides no further technical details or mitigation information.

    00000230
    20 followersView on X
  • Phanera@phaneragnosis
    Patch

    🚨 CVE-2025-22457 | Ivanti Connect Secure (ICS): unauth RCE if internet-facing (<=22.7R2.5). Patch: upgrade to 22.7R2.6+ or remove from Internet. Verify/hunt: inventory ICS versions; run Ivanti ICT. https://nvd.nist.gov/vuln/detail/CVE-2025-22457

    Post summary

    CVE-2025-22457 is an unauthenticated remote code execution vulnerability in Ivanti Connect Secure versions up to 22.7R2.5, mitigated by upgrading to 22.7R2.6+ or removing the service from the Internet.

    00000209
    12 followersView on X
CPE platform detail23 entries

23 of 23 entries

PartVendorProductVersionTarget SWTarget HW
Appivanticonnect_secure---
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivanticonnect_secure22.7--
Appivantipolicy_secure---
Appivantipolicy_secure22.7--
Appivantipolicy_secure22.7--
Appivantipolicy_secure22.7--
Appivantipolicy_secure22.7--
Appivantipolicy_secure22.7--
Appivantizero_trust_access_gateway---
Appivantizero_trust_access_gateway22.8--
Appivantizero_trust_access_gateway22.8--

Explore more