Ivanti warns of new Connect Secure flaw used in zero-day attacks
Ivanti is alerting users that hackers installed malware on appliances by taking advantage of a Connect Secure remote code execution vulnerability identified as CVE-2025-0282 in zero-day assaults.
The business claims that after the Ivanti Integrity Checker Tool (ICT) found malicious behavior on customers' equipment, it became aware of the vulnerabilities. Following an analysis, Ivanti verified that threat actors were actively using CVE-2025-0282 as a zero-day vulnerability.
An unauthenticated attacker can remotely execute code on devices thanks to a serious (9.0) stack-based buffer overflow problem in Ivanti Connect Secure prior to version 22.7R2.5, Ivanti Policy Secure prior to version 22.7R1.2, and Ivanti Neurons for ZTA gateways read more about Ivanti warns of new Connect Secure f...

