← Vulnerability feed

Vulnerability record · CVE-2025-22457 · published 3 April 2025

CVE-2025-22457: Ivanti Connect Secure, Policy Secure and ZTA Gateways stack buffer overflow RCE

Ivanti · Connect Secure

A stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to execute code. The flaw is network-reachable with no privileges or user interaction required, and it is listed in CISA KEV with confirmed ransomware campaign use, making it a top-tier perimeter risk.

9.8 CVSS 3.1 Critical CISA KEV since 4 Apr 2025 Known ransomware use EPSS 100% · top 0.1% CWE-121 · Stack-based buffer overflowCWE-787 · Out-of-bounds write
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
2References
4 Aug 2026Last modified by NVD

Description

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityRemote unauthenticated RCE on internet-facing security gateways, listed in CISA KEV with known ransomware use and an EPSS probability near 1.0.

What it is

A stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and ZTA Gateways allows a remote, unauthenticated attacker to execute code. The flaw is network-reachable with no privileges or user interaction required, and it is listed in CISA KEV with confirmed ransomware campaign use, making it a top-tier perimeter risk.

Impact

An attacker gains remote code execution on the gateway appliance, which typically sits at the network edge and can expose credentials, VPN sessions and internal network access. Successful exploitation can lead to full compromise of the device and lateral movement into protected environments.

Attack surface

Reached over the network via the affected gateway services; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed. Any internet-exposed Connect Secure, Policy Secure or ZTA Gateway instance is in scope.

Exploitation

CISA added it to KEV on 2025-04-04 with a 2025-04-11 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99981 (99.98th percentile), indicating active, near-certain exploitation.

What to do

  • Apply the vendor patches: Connect Secure 22.7R2.6, Policy Secure 22.7R1.4 and ZTA Gateways 22.8R2.2 or later.
  • Follow the CISA KEV required action and Ivanti April Security Advisory guidance, including any interim mitigations if patching is delayed.
  • Remove or restrict internet exposure of affected gateways until patched, and enforce MFA and least-privilege access on remaining remote access paths.
  • Assume compromise on unpatched, internet-facing appliances: rotate credentials and certificates, review sessions and reset devices per vendor guidance.
  • Monitor vendor and CISA advisories for updated indicators and post-exploitation guidance.

Detection

  • Hunt for crash or restart events and unexpected process terminations on Connect Secure, Policy Secure and ZTA Gateway appliances.
  • Review appliance and upstream logs for anomalous HTTP requests or exploit attempts against gateway endpoints, especially from unfamiliar source IPs.
  • Audit for unexpected new accounts, configuration changes, scheduled tasks or outbound connections originating from the gateway.
  • Correlate gateway logs with authentication and VPN session records to spot post-exploitation access or lateral movement.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-22457 to the Known Exploited Vulnerabilities catalog on 4 April 2025 as "Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations as set forth in the CISA instructions linked below. Federal deadline 11 April 2025.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-22457 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-22893Ivanti Pulse Connect Secure authentication bypass and use-after-free enabling RCEPulse Connect Secure 9.0R3/9.1R1 and higher contains an authentication bypass exposed through the Windows File Share Browser and Pulse Secure Collabo…KEVEPSS 47%analysed10.0CVE-2019-11510Pulse Connect Secure path traversal allows unauthenticated file readPulse Connect Secure versions 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 contain a path traversal (CWE-22) flaw. An unauthentica…KEVEPSS 100%analysed9.1CVE-2024-21887Ivanti Connect Secure and Policy Secure web component command injectionIvanti Connect Secure and Policy Secure (9.x, 22.x) contain a command injection flaw (CWE-77) in web components. An authenticated administrator can s…KEVEPSS 100%analysed9.0CVE-2025-0282Ivanti Connect Secure stack buffer overflow enables unauthenticated RCEA stack-based buffer overflow (CWE-121/CWE-787) in Ivanti Connect Secure, Policy Secure and Neurons for ZTA gateways lets a remote, unauthenticated a…KEVEPSS 100%analysed8.8CVE-2021-22894Pulse Connect Secure buffer overflow allows root code executionPulse Connect Secure before 9.1R11.4 contains a buffer overflow reachable through a maliciously crafted meeting room. A remote authenticated attacker…KEVEPSS 41%analysed8.8CVE-2021-22899Pulse Connect Secure command injection via Windows Resource ProfilesPulse Connect Secure before 9.1R11.4 contains a command injection flaw (CWE-77) in the Windows Resource Profiles feature. An attacker who can authent…KEVEPSS 23%analysed8.2CVE-2024-21893Ivanti Connect Secure SAML SSRF allows unauthenticated resource accessThe SAML component of Ivanti Connect Secure, Policy Secure and Neurons for ZTA contains a server-side request forgery flaw that lets an attacker reac…KEVEPSS 100%analysed8.2CVE-2023-46805Ivanti Connect Secure and Policy Secure web component authentication bypassThe web component of Ivanti Connect Secure (ICS) 9.x and 22.x and Ivanti Policy Secure fails to properly enforce authentication, letting a remote att…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2025-22457), CISA KEV, FIRST EPSS (scores of 2026-09-16). This page is refreshed as NVD updates the record.