Skip to content
Cybersecurity

Ivanti Connect Secure Zero-Day Exploited in Attacks

Ivanti Connect Secure VPN appliance affected by exploited zero-day vulnerability

A critical zero-day vulnerability in Ivanti Connect Secure VPN appliances has been exploited in attacks, allowing unauthenticated attackers to remotely execute arbitrary code on vulnerable systems. Tracked as CVE-2025-0282, the flaw is a stack-based buffer overflow affecting Ivanti Connect Secure, with exploitation confirmed by Ivanti and multiple cybersecurity agencies.

The vulnerability carries a CVSS score of 9.0 and is particularly serious because Connect Secure appliances are commonly deployed as internet-facing VPN gateways. An attacker who successfully exploits the flaw can gain code execution on the affected appliance without first authenticating to it.

Ivanti Connect Secure Zero-Day: Key Details

  • Product: Ivanti Connect Secure

  • Vulnerability: CVE-2025-0282

  • Severity: Critical

  • CVSS score: 9.0

  • Vulnerability type: Stack-based buffer overflow

  • Attack requirement: Remote, unauthenticated access

  • Impact: Remote code execution

  • Exploited in the wild: Yes

  • Affected Connect Secure versions: Versions before 22.7R2.5 at the time of disclosure

  • Related products: Ivanti Policy Secure and Ivanti Neurons for ZTA gateways were also affected by the vulnerability, although exploitation was specifically observed against Connect Secure

  • Associated malware: SPAWN, DRYHOOK and PHASEJAM

  • Recommended response: Apply the appropriate Ivanti security update and conduct compromise checks

Attackers Exploited the Flaw Before a Patch Was Available

Ivanti disclosed the vulnerability after its Integrity Checker Tool detected malicious activity on a limited number of customer appliances. The company confirmed that threat actors were actively exploiting CVE-2025-0282 as a zero-day against Connect Secure systems. The flaw was addressed in Connect Secure 22.7R2.5. Ivanti also advised administrators to run its internal and external Integrity Checker Tools and to investigate systems for signs of compromise rather than assuming that installing the patch alone would remove evidence of an earlier intrusion. The UK's National Cyber Security Centre separately confirmed active exploitation and urged organisations using affected Ivanti products to take immediate action. Its guidance included running Ivanti's external Integrity Checker Tool and carrying out a compromise assessment using indicators identified by Mandiant.

Malware Used After Initial Access

Mandiant's investigation found that attackers did more than simply gain access to vulnerable appliances. Following exploitation, threat actors deployed malware families including SPAWN, DRYHOOK and PHASEJAM, using them to maintain access, modify system behaviour and collect information. One of the observed activities involved DRYHOOK, a Python-based credential-stealing tool designed to modify a Connect Secure system component and capture successful authentication credentials. Researchers also observed attackers collecting data from the appliance's database cache. That cache can contain sensitive information associated with VPN sessions, session cookies, API keys, certificates and credential material. Mandiant observed attackers archiving the cache and placing the collected data in a location that could be accessed through the appliance's web server, creating a path for subsequent theft.

What Makes the Vulnerability Dangerous

The main risk comes from the combination of remote access and the lack of an authentication requirement. Connect Secure appliances commonly sit at the boundary between an organisation's internal network and the public internet, making an exploitable vulnerability in the appliance an attractive entry point for attackers. CVE-2025-0282 is separate from CVE-2025-0283, another vulnerability disclosed at the same time. CVE-2025-0283 is also a stack-based buffer overflow, but it requires an authenticated local attacker and can be used for privilege escalation. Ivanti said CVE-2025-0283 was not being exploited in the attacks involving CVE-2025-0282.

Organisations Need More Than a Patch

Because CVE-2025-0282 was exploited as a zero-day, organisations cannot assume that an appliance is safe simply because it has subsequently been updated. A vulnerable system may have been compromised before the security update was installed. The NCSC recommends checking affected appliances with Ivanti's Integrity Checker Tool and conducting a broader compromise assessment. Organisations that find evidence of intrusion should investigate associated accounts, credentials, certificates and other secrets that may have been exposed through a compromised VPN appliance.

Ivanti has also continued to strengthen Connect Secure. In September 2025, the company released Connect Secure 25.X with a redesigned operating system, SELinux enforcement, Secure Boot, encryption and other hardening measures intended to reduce the attack surface of the VPN platform. The incident demonstrates why internet-facing VPN appliances remain a high-value target for attackers. A single remotely exploitable vulnerability can provide an entry point into an organisation's access infrastructure, while follow-on malware can turn that initial compromise into credential theft and broader network access.