Ivanti Connect Secure stack-based buffer overflow (CVE-2025-22457) — devices placed to join outside and inside become the most targeted position
A stack-based buffer overflow in Ivanti Connect Secure and related products. A remote unauthenticated party is described as able to achieve remote code execution. The remediation deadline was seven days, and the required action points to instructions issued by CISA.
Key facts
- CVE IDCVE-2025-22457
- Affected (vendor / product)Ivanti Connect Secure, Policy Secure, and ZTA Gateways
- CWECWE-121
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2025-04-11 (U.S. federal civilian agencies, BOD 22-01)
Key points
- The affected products are Ivanti Connect Secure, Policy Secure and ZTA Gateways, classified as CWE-121.
- A remote unauthenticated party is described as able to achieve remote code execution.
- The due date was seven days, shorter than the standard 21, and use in ransomware campaigns is known.
- The required action points to instructions issued by the authority rather than vendor guidance alone.
- Across the records this site holds as of 2026-09-04, boundary and VPN entries with known ransomware use number 59, the largest grouping.
1Placed to join outside and inside
A device for reaching internal resources remotely sits, by definition, where both outside and inside can reach it. It is useless if it accepts no connections from outside and pointless if it does not lead inward. That position is itself what makes it a target.
Across the records this site holds as of 2026-09-04, 59 unpublished entries fall to major boundary or VPN vendors and are marked as known in ransomware campaigns — the largest grouping under the placement categories used here.
2Overwriting the stack
When a program calls a function it places what it needs on a region called the stack, including where to return once the work is done. Writing beyond the size reserved can replace that return information as well.
This site separately covers the neighbouring class of out-of-bounds writes. Stack-based names the subset occurring in the stack region.
3A specific procedure named in the required action
- 1Most entriesApply mitigations per vendor instructions
- 2Also usualDiscontinue use where mitigations are unavailable
- 3This entryStates that mitigations set forth in CISA instructions are to be applied
- 4What that meansA procedure exists from the authority, apart from vendor guidance
A reference to a specific procedure from the authority is not common in required actions. Such wording appears where applying an update alone is judged insufficient, or where particular checks are called for. It should be read together with the deadline compressed to seven days.
4Why these are hard to defend
Devices of this kind presume reachability from outside, so limiting where connections may originate is harder than elsewhere. This site covers an entry whose required action states that management interfaces should not be exposed to untrusted networks, yet the port through which users connect cannot itself be closed. Applying updates promptly therefore carries more weight here than for other devices.
Why it matters
Devices presuming reachability from outside cannot easily restrict where connections originate, so prompt updating carries more weight than elsewhere. Short deadlines cluster in this grouping.
FAQ
Why are boundary devices targeted?
What does stack-based mean?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).