Skip to main content

Connect Secure, Policy Secure, and ZTA Gateways vulnerabilities

2 published alerts for Ivanti Connect Secure, Policy Secure, and ZTA Gateways.

Actively exploited (KEV)Ransomware

CVE-2025-22457

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-22457). Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution. CISA remediation due date: 2025-04-11. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-0282

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-0282). Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution. CISA remediation due date: 2025-01-15. If you need help checking exposure, call (864) 335-9223.