CISA (Cybersecurity and Infrastructure Security Agency) and the NCSC-UK (National Cyber Security Centre – United Kingdom) have both reported active exploitation of CVE-2025-0282 in the wild. Ivanti has acknowledged that a limited number of its customers have been affected by these vulnerabilities, prompting the urgency to address the issues.
The affected versions of Ivanti’s products include:
– Ivanti Connect Secure, versions prior to 22.7R2.5
– Ivanti Policy Secure, versions prior to 22.7R1.2
– Ivanti Neurons for ZTA Gateways, versions prior to 22.7R2.3
Given the severity of these vulnerabilities, CERT-SE recommends that users immediately update their software in accordance with the guidelines provided by Ivanti to mitigate the risks associated with these security flaws.
For detailed guidance and remediation steps, Ivanti has released a security advisory, and additional information can be found through CISA and the NCSC-UK, emphasizing the necessity for prompt action to protect systems against potential exploitation.
Enlace de la fuente, haz clic para tener más información