Skip to content

CVE Brief · Aug 8, 2026

CVE Brief: CVE-2025-0282 in Ivanti Secure Gateways

A sourced brief on CVE-2025-0282, an actively exploited unauthenticated remote-code-execution vulnerability affecting Ivanti secure gateway products.

#cve#vulnerability#analysis

This learner brief summarizes the vendor and government guidance available for CVE-2025-0282. Operational decisions should always follow the latest Ivanti advisory.

What the vulnerability is

CVE-2025-0282 is a stack-based buffer overflow affecting Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for ZTA gateways. A remote attacker can reach the vulnerable condition without authentication and achieve remote code execution.

Ivanti assigned it a CVSS 3.1 base score of 9.0 (Critical). CISA added the CVE to its Known Exploited Vulnerabilities catalog on January 8, 2025 after evidence of active exploitation.

Affected versions

The CVE record describes these affected version ranges:

  • Ivanti Connect Secure versions before 22.7R2.5
  • Ivanti Policy Secure versions before 22.7R1.2
  • Ivanti Neurons for ZTA gateways versions before 22.7R2.3

Because vendor advisories can be revised, confirm the exact supported release and upgrade path for each appliance directly with Ivanti before returning it to service.

Why it demands urgent attention

These products commonly sit at a network boundary and provide remote access. The combination of pre-authentication reachability, remote code execution, and confirmed exploitation makes this an incident-response concern—not only a routine patching task.

Defensive response

  1. Inventory every Connect Secure, Policy Secure, and Neurons for ZTA gateway, including appliances not currently exposed to the public internet.
  2. Follow Ivanti's current integrity-check, upgrade, and recovery instructions for the specific product and release.
  3. Apply CISA's hunt and remediation guidance. Treat suspicious integrity-check results or indicators as potential compromise and preserve evidence for response.
  4. Apply the required update before returning an affected device to service.
  5. Review authentication, administrative, network, and downstream-system telemetry for activity associated with the gateway.

Sources