>> All posts

CVE-2025-22457: Ivanti Connect Secure stack buffer overflow, unauthenticated RCE, actively exploited

The short version: CVE-2025-22457 is a stack-based buffer overflow in Ivanti Connect Secure (and Policy Secure and Ivanti ZTA Gateways) that lets a remote, unauthenticated attacker achieve remote code execution on the appliance. It's been exploited in the wild and is in CISA's KEV catalog. If you run an affected build, patch and verify. Steady hands — but move.

At a glance

FactDetail
Our severity takeCritical — unauthenticated RCE on a perimeter appliance, exploited in the wild
CVSS v3.1 (NVD)9.0 — Critical · AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS~99.98% · 99.98th percentile (2026-07-17)
In CISA KEV?Yes — remediation was due 2025-04-11
Known exploited?Yes — exploited in the wild (KEV notes known ransomware-campaign use)
Vulnerability typeCWE-121 stack-based buffer overflow → unauthenticated remote code execution
Requires authenticated session?No — pre-authentication
AffectedIvanti Connect Secure < 22.7R2.6; Ivanti Policy Secure < 22.7R1.4; Ivanti ZTA Gateways < 22.8R2.2
Fixed inConnect Secure 22.7R2.6 · Policy Secure 22.7R1.4 · ZTA Gateways 22.8R2.2

What you need to know

CVE-2025-22457 is a memory-safety flaw: a crafted request overflows a fixed-size stack buffer in Connect Secure, and an unauthenticated attacker leverages that to run code on the appliance. The base vector notes high attack complexity (AC:H) — the overflow initially looked like a low-severity denial-of-service — but attackers turned it into reliable remote code execution.

Why it belongs at the top of the queue:

  • It's pre-authentication and network-reachable. No credentials, no chain required.
  • It's a perimeter security appliance. Code execution on Connect Secure means control of the device that terminates remote access into your network.
  • It's confirmed exploited. CISA added it to KEV and flags known ransomware-campaign use, so the theoretical is operational.

How serious we see it

Critical — in practice and on paper.

Unauthenticated remote code execution on an internet-facing access gateway, confirmed exploited in the wild, is the definition of top-of-queue. The high-complexity metric is not much comfort once a working exploit exists. The bounded, reassuring part: it affects specific builds, the fixes are published, and exposure is quick to determine — but because it was exploited before many organizations patched, being patched and being clean are separate questions.

Recommendations

Straight from Ivanti's advisory and CISA:

  1. Patch now. Upgrade to Connect Secure 22.7R2.6 / Policy Secure 22.7R1.4 / ZTA Gateways 22.8R2.2 or later.
  2. Hunt for compromise. Run Ivanti's external Integrity Checker Tool and review appliance logs for signs of exploitation.
  3. If compromised, respond fully. Rebuild from a known-good image and rotate all credentials, keys, and certificates the appliance held.
  4. Harden exposure. Restrict who can reach the gateway; keep the management interface off the public internet.
  5. Confirm your exposure first. Verify whether you run an affected build.

How BreachRisk sees it

BreachRisk works from the outside in. From little more than your domain it discovers internet-facing Ivanti Connect Secure, Policy Secure, and ZTA Gateway interfaces, fingerprints the product and version, and flags exposure tied to KEV-listed, actively exploited vulnerabilities like this one — surfaced at the top of your results because it's in KEV.

When an access-gateway zero-day breaks, that continuous, attacker's-eye view means the exposed appliance is already mapped — so you go straight to patch-and-verify.

References

See your cyber risk, proven.