CVE-2025-22457
KEV · ransomware Critical · CVSS 9.0- CVSS
- 9.0
- nvd
- EPSS
- —
- KEV
- Listed
- ransomware
- Class
- other
- CWE-121, CWE-787
Description
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
References
Status: profiled · ingested 2026-08-04T06:00:54.000Z