Ivanti remediated CVE-2025-0282, a CVSS 9.0 unauthenticated remote-code-execution flaw affecting Ivanti Connect Secure and Policy Secure appliances. Ivanti warned that the vulnerability was being actively exploited, and public proof-of-concept code was released, increasing the risk of opportunistic compromise. The company also fixed CVE-2025-0283, a CVSS 7.0 local privilege-escalation vulnerability.
Organizations should apply Ivanti’s updates immediately and use the Ivanti Integrity Checker Tool to identify indicators of compromise. Where compromise is detected, Ivanti advises resetting affected appliances to factory defaults and following its recovery process; defenders should also monitor surrounding networks and credentials for malicious activity or persistence.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers published proof-of-concept code for CVE-2025-0282, increasing the likelihood of broader exploitation of the actively exploited Connect Secure vulnerability.
Ivanti remediated CVE-2025-0282, an actively exploited unauthenticated remote code-execution flaw in Connect Secure, and CVE-2025-0283, a local privilege-escalation flaw affecting Connect Secure and Policy Secure. Ivanti also released its Integrity Checker Tool and Mandiant published related indicators of compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.