CVE-2025-22457: Hackers Actively Exploiting Ivanti’s Critical New Flaw
Red | Vulnerability Report
Download PDFIvanti disclosed a critical vulnerability (CVE-2025-22457) affecting Ivanti Connect Secure, Pulse Connect Secure, and other gateway products. The stack-based buffer overflow flaw enables remote, unauthenticated attackers to execute arbitrary code. Initially seen as a low-risk bug and patched in February 2025, it has been actively exploited since mid-March by suspected Chinese threat actors deploying TRAILBLAZE and BRUSHFIRE malware. Ivanti patched Connect Secure in v22.7R2.6, and organizations must update or migrate unsupported systems immediately.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox