Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityperimeter-device-exposuregovernment-vulnerability-catalogwidely-deployed-product-advisory

Ivanti Connect Secure RCE Flaws Exploited, Legacy Pulse Secure Left Unpatched

Updated 2mo agoFirst seen Apr 14, 20263 sources

Ivanti disclosed multiple critical vulnerabilities affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA Gateway, including CVE-2025-0282 (CVSS 9.0), a stack-based buffer overflow that allows unauthenticated remote code execution, and CVE-2025-0283 (CVSS 7.0), which enables privilege escalation. Ivanti said CVE-2025-0282 has been exploited in the wild against Ivanti Connect Secure, prompting urgent guidance for organizations to upgrade to fixed releases and use the Integrity Checker Tool to look for signs of compromise.

Authorities later warned that CVE-2025-22457 is also being actively exploited in Ivanti Connect Secure and Pulse Connect Secure, allowing remote command execution on vulnerable systems. Ivanti Connect Secure addressed that flaw in version 22.7R2.6, but Pulse Connect Secure 9.x has no patch and will not receive one, leaving migration and retirement as the only mitigation for legacy deployments. While Ivanti Policy Secure and ZTA Gateway are also affected by CVE-2025-22457, exploitation had not been observed in those products at the time of reporting.

Share:
Ivanti Connect Secure RCE Flaws Exploited, Legacy Pulse Secure Left Unpatched
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 3, 20251y ago

Finnish NCSC contacts organizations still running outdated Ivanti versions

The Finnish National Cyber Security Centre said most domestic organizations had already updated affected systems and that it had contacted some organizations still using older vulnerable versions. The outreach followed reports of exploitation in older Ivanti and Pulse deployments.

Active exploitation of CVE-2025-22457 reported in Ivanti and Pulse products

Active exploitation of CVE-2025-22457 was reported in Ivanti Connect Secure and legacy Pulse Connect Secure systems. Pulse Connect Secure 9.x had no patch and no planned future fix, prompting guidance to migrate away from the unsupported product.

Feb 1, 20251y ago

Ivanti releases fix for CVE-2025-22457 in Connect Secure

Ivanti released version 22.7R2.6 for Ivanti Connect Secure in February to fix CVE-2025-22457, a flaw that can enable remote command execution. The issue also affected Ivanti Policy Secure and ZTA Gateway, though exploitation was not observed in those products.

Jan 8, 20251y ago

Ivanti discloses CVE-2025-0282 and CVE-2025-0283 with active exploitation

Ivanti disclosed critical vulnerabilities affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA Gateway. It said CVE-2025-0282, a remote code execution flaw, had already been exploited in Ivanti Connect Secure, while CVE-2025-0283 allowed privilege escalation.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

7 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.