{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/policy-secure-22.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ivanti:connect_secure:22.7:r2:*:*:*:*:*:*","cpe:2.3:a:ivanti:connect_secure:22.7:r2.1:*:*:*:*:*:*","cpe:2.3:a:ivanti:connect_secure:22.7:r2.2:*:*:*:*:*:*","cpe:2.3:a:ivanti:connect_secure:22.7:r2.3:*:*:*:*:*:*","cpe:2.3:a:ivanti:connect_secure:22.7:r2.4:*:*:*:*:*:*","cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.7:r2:*:*:*:*:*:*","cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.7:r2.2:*:*:*:*:*:*","cpe:2.3:a:ivanti:neurons_for_zero-trust_access:22.7:r2.3:*:*:*:*:*:*","cpe:2.3:a:ivanti:policy_secure:22.7:r1:*:*:*:*:*:*","cpe:2.3:a:ivanti:policy_secure:22.7:r1.1:*:*:*:*:*:*","cpe:2.3:a:ivanti:policy_secure:22.7:r1.2:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9,"id":"CVE-2025-0282"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Connect Secure (22.7)","Policy Secure (22.7)","Neurons for Zero-trust Access (22.7)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","ivanti"],"_cs_type":"advisory","_cs_vendors":["Ivanti"],"content_html":"\u003cp\u003eCVE-2025-0282 is a critical stack buffer overflow vulnerability impacting multiple Ivanti products, including Ivanti Connect Secure, Ivanti Policy Secure, and Ivanti Neurons for Zero-trust Access, specifically version 22.7. The vulnerability exists within the unauthenticated interface, allowing remote attackers to trigger the overflow without prior access credentials. Proof-of-concept exploit code is publicly available, utilizing ROP chains to achieve code execution. Research indicates that successful exploitation leads to the creation of a local administrative account with root-level privileges (UID 0), granting the attacker full control over the appliance. Defenders should prioritize patching, as the presence of public exploit scripts significantly increases the risk of targeted exploitation against internet-facing appliances.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2025-0282 results in complete system compromise. By creating a persistent administrative account, an attacker can maintain long-term access, facilitate lateral movement within the network, and exfiltrate sensitive data managed by the Ivanti gateway. Given the criticality of these appliances as entry points for remote access, the risk to confidentiality, integrity, and availability is high.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately identify and patch all internet-facing Ivanti Connect Secure, Policy Secure, and Neurons for Zero-trust Access appliances running version 22.7.\u003c/li\u003e\n\u003cli\u003eReview administrative user account logs for the creation of unexpected accounts or modifications to existing accounts.\u003c/li\u003e\n\u003cli\u003eRestrict access to administrative and management interfaces to trusted internal IP ranges or VPN-only access to reduce the attack surface.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous outbound network traffic from Ivanti appliances, which may indicate post-exploitation activity or C2 communication.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T01:48:00Z","date_published":"2026-09-03T01:48:00Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-0282/","summary":"A critical unauthenticated stack buffer overflow in Ivanti Connect Secure, Policy Secure, and Neurons for Zero-trust Access (version 22.7) allows remote attackers to execute arbitrary code and create unauthorized administrative accounts.","title":"Unauthenticated RCE in Ivanti Connect Secure via CVE-2025-0282","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2025-0282/"}],"language":"en","title":"CraftedSignal Threat Feed - Policy Secure (22.7)","version":"https://jsonfeed.org/version/1.1"}