Site icon TheCyberThrone

CISA adds Ivanti Connect Secure to KEV Catalog

Advertisements

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Ivanti Connect Secure to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability, identified as CVE-2025-22457, is a stack-based buffer overflow that allows unauthenticated attackers to execute arbitrary code remotely, potentially gaining full control of affected systems.

Details of CVE-2025-22457

CISA’s Recommendations

CISA strongly urges organizations to:

Apply Patches:

Conduct Threat Hunting:

Isolate and Reset:

Monitor Privileged Accounts:

This addition to the KEV Catalog underscores the critical nature of this vulnerability and the importance of timely remediation to protect against active exploitation.

Exit mobile version