Exploited Known exploited (KEV) Ransomware use CVE-2025-22457

Ivanti Connect Secure stack-based buffer overflow (CVE-2025-22457) — devices placed to join outside and inside become the most targeted position

Ivanti Connect Secure, Policy Secure, and ZTA Gateways Added to KEV Apr 4, 2025 Federal remediation due 2025-04-11

A stack-based buffer overflow in Ivanti Connect Secure and related products. A remote unauthenticated party is described as able to achieve remote code execution. The remediation deadline was seven days, and the required action points to instructions issued by CISA.

Key facts

  • CVE IDCVE-2025-22457
  • Affected (vendor / product)Ivanti Connect Secure, Policy Secure, and ZTA Gateways
  • CWECWE-121
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2025-04-11 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected products are Ivanti Connect Secure, Policy Secure and ZTA Gateways, classified as CWE-121.
  • A remote unauthenticated party is described as able to achieve remote code execution.
  • The due date was seven days, shorter than the standard 21, and use in ransomware campaigns is known.
  • The required action points to instructions issued by the authority rather than vendor guidance alone.
  • Across the records this site holds as of 2026-09-04, boundary and VPN entries with known ransomware use number 59, the largest grouping.

1Placed to join outside and inside

A device for reaching internal resources remotely sits, by definition, where both outside and inside can reach it. It is useless if it accepts no connections from outside and pointless if it does not lead inward. That position is itself what makes it a target.

Entries this site holds as of 2026-09-041,694100 with published articles
Entries at that date from major boundary and VPN vendors with known ransomware use59Counted across the unpublished records
Due date hereSeven daysAgainst a standard of 21 days, held by 1,025 entries at the same date

Across the records this site holds as of 2026-09-04, 59 unpublished entries fall to major boundary or VPN vendors and are marked as known in ransomware campaigns — the largest grouping under the placement categories used here.

2Overwriting the stack

When a program calls a function it places what it needs on a region called the stack, including where to return once the work is done. Writing beyond the size reserved can replace that return information as well.

What is intendedWhere the flaw exists
Writing stays inside the reserved rangeWriting exceeds it and overwrites other stack contents
Control returns to the caller when doneThe return information may be replaced
The program decides the flowThe flow may be influenced from outside

This site separately covers the neighbouring class of out-of-bounds writes. Stack-based names the subset occurring in the stack region.

3A specific procedure named in the required action

  1. 1Most entriesApply mitigations per vendor instructions
  2. 2Also usualDiscontinue use where mitigations are unavailable
  3. 3This entryStates that mitigations set forth in CISA instructions are to be applied
  4. 4What that meansA procedure exists from the authority, apart from vendor guidance

A reference to a specific procedure from the authority is not common in required actions. Such wording appears where applying an update alone is judged insufficient, or where particular checks are called for. It should be read together with the deadline compressed to seven days.

4Why these are hard to defend

Devices of this kind presume reachability from outside, so limiting where connections may originate is harder than elsewhere. This site covers an entry whose required action states that management interfaces should not be exposed to untrusted networks, yet the port through which users connect cannot itself be closed. Applying updates promptly therefore carries more weight here than for other devices.

Why it matters

Devices presuming reachability from outside cannot easily restrict where connections originate, so prompt updating carries more weight than elsewhere. Short deadlines cluster in this grouping.

FAQ

Why are boundary devices targeted?
They sit where outside can reach them and inside lies beyond. That position is required by their role, and limiting where connections originate is correspondingly hard.
What does stack-based mean?
An out-of-bounds write occurring in the stack, the region used for function calls, where the information about where to return may be replaced.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#VPN#Boundary devices
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.