Ivanti has revealed information on a significant security flaw in its Connect Secure that has been fixed and is currently being actively exploited in the wild.
With a CVSS score of 9.0, the vulnerability, identified as CVE-2025-22457, relates to a stack-based buffer overflow scenario that might be used to run arbitrary code on compromised systems.
Ivanti said in an alert issued Thursday that a remote unauthenticated attacker might execute code remotely using a stack-based buffer overflow in Ivanti Connect Secure prior to version 22.7R2.6, Ivanti Policy Secure prior to version 22.7R1.4, and Ivanti ZTA Gateways prior to version 22.8R2.2.
The business stated that it is aware of a “limited number of customers” that have end-of-support Pulse and Connect Secure read more about Critical Ivanti Flaw Actively Exploited to Deploy TRAILBLAZE and BRUSHFIRE Malware.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
