Vulnary
← back to the feed
Critical· 9actively exploitedofficial fix available

CVE-2025-0282

A critical vulnerability in Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways allows remote attackers to execute arbitrary code without authentication. The flaw is a stack-based buffer overflow that can be triggered over the network. It affects versions before 22.7R2.5, 22.7R1.2, and 22.7R2.3 respectively.

publishedJan 8, 2025
last modifiedAug 4, 2026
sourcesNVD · CISA-KEV
severity · cvss
9
critical · how bad it is
exploitation · epss
100%
100th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 3, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for Zero Trust Access gateways, all versions 22.7 and earlier (before 22.7R2.5, 22.7R1.2, and 22.7R2.3). Typical users are organizations deploying these products for secure remote access and zero‑trust networking.

02

Real-world impact

An attacker could run arbitrary code on the affected system, potentially taking full control, stealing data, or using the device as a foothold for further attacks.

03

Why this severity

The CVSS score of 9 reflects the high impact of remote code execution (confidentiality, integrity, availability all high) combined with the difficulty of exploitation (high attack complexity) but no user interaction or authentication required.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade Ivanti Connect Secure to version 22.7R2.5 or later.
  2. 02Upgrade Ivanti Policy Secure to version 22.7R1.2 or later.
  3. 03Upgrade Ivanti Neurons for ZTA gateways to version 22.7R2.3 or later.
  4. 04Restart the affected services after the update.
interim mitigations
  • Conduct hunt activities to identify compromised devices.
  • Isolate affected devices until the update is applied.

CISA KEV required action

05

Timeline

  1. Jan 8, 2025 · Jan 8, 2025
    Confirmed exploited (CISA KEV)
    CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
  2. Jan 8, 2025 · Jan 8, 2025
    Published
    Disclosed and added to the National Vulnerability Database.
  3. Jan 15, 2025 · Jan 15, 2025
    CISA remediation deadline
    Federal agencies are required to remediate by this date.
  4. Aug 4, 2026 · 2d ago
    Advisory updated
    The NVD record was last revised.
  5. Aug 4, 2026 · 2d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityHigh
Privileges requiredNone
User interactionNone needed
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →