Vulnary
← back to the feed
Critical· 9actively exploitedofficial fix available

CVE-2025-22457

A critical security flaw in certain Ivanti security products allows an attacker to run their own code on the system remotely. This vulnerability is caused by a memory error known as a stack-based buffer overflow.

publishedApr 3, 2025
last modifiedAug 4, 2026
sourcesNVD · CISA-KEV
severity · cvss
9
critical · how bad it is
exploitation · epss
100%
100th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 3, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

Users of Ivanti Connect Secure (versions before 22.7R2.6), Ivanti Policy Secure (versions before 22.7R1.4), and Ivanti ZTA Gateways (versions before 22.8R2.2).

02

Real-world impact

An attacker could take complete control of the affected Ivanti device without needing any login credentials, potentially allowing them to steal sensitive data or disrupt network services.

03

Why this severity

This vulnerability is rated critical because it allows a remote attacker to execute code with high impact on confidentiality, integrity, and availability, even though it requires high complexity to exploit.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade Ivanti Connect Secure to version 22.7R2.6 or later.
  2. 02Upgrade Ivanti Policy Secure to version 22.7R1.4 or later.
  3. 03Upgrade Ivanti ZTA Gateways to version 22.8R2.2 or later.
interim mitigations
  • Apply mitigations as set forth in the CISA instructions.

CISA KEV required action

05

Timeline

  1. Apr 3, 2025 · Apr 3, 2025
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Apr 4, 2025 · Apr 4, 2025
    Confirmed exploited (CISA KEV)
    CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
  3. Apr 11, 2025 · Apr 11, 2025
    CISA remediation deadline
    Federal agencies are required to remediate by this date.
  4. Aug 4, 2026 · 2d ago
    Advisory updated
    The NVD record was last revised.
  5. Aug 4, 2026 · 2d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityHigh
Privileges requiredNone
User interactionNone needed
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →