Known vulnerability record

CVE-2025-22457

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Stable IDcve:CVE-2025-22457Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability

Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.

Keep the signals separate

CVSS severitycriticalScore 9 · source ivanti
EPSS probability100.0%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2025-04-04
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2025-04-03
CVE modified
2026-08-04
KEV date added
2025-04-04
Dataset fetched
2026-08-21T03:55:10.914Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.