Vulnerability threat dossier

CVE-2025-22457

ivanticonnect secure

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

VTP deterministic threat62.0of 100 · CVSS excluded

VTP analyst assessment

Ivanti edge-appliance buffer overflow

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV

Assessment

Critical stack-based buffer overflow in specified Ivanti Connect Secure, Policy Secure, and ZTA Gateway releases enables unauthenticated remote code execution, although attack complexity is high. Public known exploitation and known ransomware-campaign use are recorded; VTP observation is unknown.

Why it matters

  • Affected edge appliances are remotely reachable attack surfaces, and successful exploitation can yield high-impact code execution.
  • The 0.9998 EPSS score is predictive context only.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 1 independent evidence group.

Uncertainties

The bundle does not define the high-complexity conditions or establish public exploit reliability.

The listed exploit-source excerpt does not clearly identify this CVE, and first-party activity is unknown.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Malformed traffic or crashes on exposed Ivanti appliance interfaces.

AI baseline history (2)
  1. BASELINE ASSESSED
    Ivanti edge-appliance buffer overflowgpt-5.6-sol · high
  2. BASELINE ASSESSED
    Ivanti gateway unauthenticated remote code executiongpt-5.6-sol · high
Technical severityCRITICALCVSS 9.0 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence95%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  3. 03

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

1 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimACTIVE EXPLOITATIONENISA EU KEV LISTED
95%claim confidence
INDEPENDENTcatalog:enisa-eu-kev:CVE-2025-22457ACTIVE
Evidence
04

Event history

Threat timeline

  1. 15:2328 May
    EXPLOIT SOURCE UPDATE

    New exploit-source update

    ProjectDiscovery Nuclei Templates Releases published evidence linked to CVE-2025-22457.

  2. 00:0004 Apr
    ACTIVE EXPLOITATION

    ENISA EU KEV entry added

    ENISA EU KEV reports known exploitation. VTP imported this historical entry as source baseline. This is public intelligence, not a VTP sensor observation.

  3. 00:0004 Apr
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Nuclei Templates v10.4.4 - Release Notes

New Templates Added: 179 | CVEs Added: 43 | First-time contributions: 20 🔥 Release Highlights 🔥 [ CVE-2026-47668 ] DbGate - Remote Code Execution via Anonymous JWT ( @benharvey-sage ) [critical] 🔥 [ CVE-2026-46725 ] TYPO3 ceselector Extension - Insecure Deserialization ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-44578 ] Next.js WebSocket Upgrade Handler - SSRF ( @hacktron , @dhiyaneshdk ) [high] 🔥 [ CVE-2026-34486 ] Apache Tomcat Tribes EncryptInterceptor Bypass - Remote Code Execution ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-33453 ] Apache Camel camel-coap - Remote Code Execution ( @dhiyaneshdk ) [critical] 🔥 [ CVE-2026-25545 ] Astro SSR - Server-Side Request Forgery ( @ritikchaddha ) [high] 🔥 [ CVE-2026-20182 ] Cisco Catalyst SD-WAN Controller - vHub Auth Bypass ( @sfewer-r7 , @Crypto-Cat ,.) [critical] 🔥 (kev) (vKEV) [ CVE-2026-9082 ] Drupal Core - SQL Injection via PostgreSQL Entity Query ( @slcyber , @dhiyaneshdk ) [critical] 🔥 (kev) (vKEV) [ CVE-2026-8181 ] WordPress Burst Statistics 3.4.0-3.4.1.1 - Auth Bypass (@0x_Akoko) [critical] 🔥 (kev) (vKEV) [ CVE-2026-5718 ] Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - RCE( @zer0p0int ) [critical] 🔥 (kev) (vKEV) [ CVE-2026-4810 ] Google ADK-Python - Unauthenticated Builder Endpoint ( @dwisiswant0 ) [critical] 🔥 [ CVE-2026-0740 ] Ninja Forms File Uploads <= 3.3.26 - Arbitrary File Upload ( @whattheslime ) [critical] 🔥 (kev) (vKEV) [ CVE-2026-0545 ] MLflow Job API - Auth Bypass ( @dhiyaneshdk ) [critical] 🔥 [CVE-2025-62168] Squid Proxy - HTTP Auth Credentials Disclosure (@xtr0nix) [critical] 🔥 [ CVE-2025-34030 ] sar2html <=3.2.2 Plot Parameter - Remote Code Execution ( @gy741 , @TATANKA97 ) [critical] 🔥 (kev) (vKEV) [CVE-2025-32778] Web-Check < 2.0.1 Screenshot API - OS Command Injection ( @gugacyber ) [critical] 🔥 (kev) (vKEV) [ CVE-2024-32114 ] Apache ActiveMQ 6.x < 6.1.2 - Broken Access Control ( @ChrisJr404 ) [high] 🔥 (kev) (vKEV) What's Changed Bug Fixes Corrected the classification.cve-id mismatch in the CVE-2024-38856 template, which was pointing to CVE-2024-32113 (PR #16277 ). Fixed a YAML parsing failure in gradio-image-ssrf caused by an unclosed string literal in DSL matchers, after the stricter govaluate fork surfaced it (PRs #16171 , #16210 , #16243 ). Added the missing cve-id classification to CVE-2023-2745 (PR #16152 ). Added the missing words key in CVE-2023-46347 , which previously caused a YAML syntax error and prevented execution (PR #16097 ). Resolved a duplicate template id conflict for fortisandbox-panel by renaming the Fortinet-scoped template (PR #16070 ) and removed the leftover duplicate plus stray contrastapi recon templates as release-prep cleanup (PR #16118 ). Renamed the malware template id from ransomware_windows_hydracrypt for consistency (PR #16114 ). Renamed the eol-magento template id to magento-eol to follow naming conventions (PR #16154 ). Relocated opendcim-detect.yaml out of the non-existent http/detect folder (PR #16266 ). Removed unused extractors from CVE-2025-13418 (PR #16204 ). False Negatives - CVE-2023-2745 : removed an unnecessary authentication requirement so the template fires against unauthenticated targets (Issue #16133 , PR #16139 ). - CVE-2021-40438 : added support for custom Interactsh server hostnames so detection no longer requires the oast* naming convention (Issue #12074 , PR #16052 ). False Positives - CVE-2026-3844 (Issue #16124 , PR #16161 ). - CVE-2025-22457 (Issue #15955 , PR #16162 ). - http-missing-security-headers: dropped the clear-site-data matcher on the base URL (Issue #12008 , PR #16050 ) and unanchored the Content-Type regexes so matches are position-independent (PR #16125 ). - workspace-one-uem panel: removed a matcher that misfired on paths placed inside content="" attributes (PR #16117 ). Enhancements Enhanced CVE-2026-33017 by removing the redundant build_public_tmp exploit request that relied on a null flow UUID (Issue #16134 , PR #16149 ). Converted legacy http/vulnerabilities template

CVE-2019-25246CVE-2020-10532CVE-2021-24916CVE-2021-40438CVE-2021-4463CVE-2022-0218CVE-2023-2745CVE-2023-46347CVE-2023-7327CVE-2024-10763CVE-2024-32113CVE-2024-32114CVE-2024-36420CVE-2024-38856CVE-2024-4322CVE-2024-48259CVE-2024-9362CVE-2025-12841CVE-2025-13418CVE-2025-14726CVE-2025-22457CVE-2025-32778CVE-2025-32966CVE-2025-34030CVE-2025-47577CVE-2025-48157CVE-2025-62168CVE-2026-0545CVE-2026-0740CVE-2026-20182CVE-2026-25545CVE-2026-26341CVE-2026-32230CVE-2026-33017CVE-2026-33453CVE-2026-33534CVE-2026-34486CVE-2026-34847CVE-2026-38360CVE-2026-38361CVE-2026-3844CVE-2026-39352CVE-2026-40878CVE-2026-42281CVE-2026-42569CVE-2026-44578CVE-2026-46372CVE-2026-46670CVE-2026-46725CVE-2026-47668CVE-2026-4810CVE-2026-5718CVE-2026-6433CVE-2026-8181CVE-2026-8679CVE-2026-9082
Separate evidence group
Original

ENISA EU KEV catalog membership for CVE-2025-22457

ENISA EU KEV lists this vulnerability as known to be exploited. This is public intelligence, not a VTP sensor observation.

CVE-2025-22457
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score62.0vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction20 / 20
Exploit availability2.5 / 15
Source independence7.5 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE
CWE-121, CWE-787
CPE records
23
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.