Ivanti has disclosed a critical vulnerability, CVE-2025-22467, impacting its Connect Secure (ICS) product. This stack-based buffer overflow vulnerability, rated 9.9 (Critical) on the CVSS v3.1 scale, allows remote authenticated attackers to execute arbitrary code on affected systems.
The flaw is present in versions up to 22.7R2.5 and has been addressed in the latest release, 22.7R2.6.
CVE-2025-22467 is classified under CWE-121: Stack-Based Buffer Overflow, a common and critical vulnerability type that occurs when data written to a buffer exceeds its allocated size, corrupting adjacent memory locations.
This specific flaw allows attackers with low privileges to exploit the system remotely without user interaction.
The attack vector is network-based, with low complexity, and it can compromise confidentiality, integrity, and availability at a high impact level.
“We are not aware of any customers being exploited by these vulnerabilities prior to public disclosure”, reads the advisory.
The following table outlines the affected and resolved versions:
| Product Name | Affected Versions | Resolved Versions |
| Ivanti Connect Secure | 22.7R2.5 and below | 22.7R2.6 |
Ivanti urges all users to update their systems immediately to version 22.7R2.6 or later to mitigate the risk of exploitation. For organizations unable to patch immediately, Ivanti recommends the following interim measures:
This disclosure follows a series of vulnerabilities reported in Ivanti products over recent years, including code injection flaws (CVE-2024-10644) and arbitrary file read issues (CVE-2024-12058).
Historical exploitation of Ivanti Connect Secure has been observed by advanced persistent threat (APT) groups and cybercriminals targeting similar vulnerabilities.
The critical nature of CVE-2025-22467 highlights the importance of maintaining up-to-date software and implementing robust cybersecurity practices.
Organizations using Ivanti Connect Secure should prioritize patching their systems to version 22.7R2.6 or later without delay.
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…