A critical vulnerability CVE-2025-0282 has been identified in Ivanti Connect Secure prior to 22.7R2.5, Ivanti Policy Secure prior to 22.7R1.2, and Ivanti Neurons for ZTA gateways prior to 22.7R2.3. The vulnerability is a stack-based buffer overflow that can lead to remote code execution (RCE).
While no public exploit is currently available, there are reports of environments being targeted. Update from January13: The IONIX research team developed and tested an exploit simulation on relevant assets to verify the vulnerability’s impact and assess potential exposure. The findings are detailed in this post. Ivanti has released a patch addressing this vulnerability
References:

