Ivanti has published a security bulletin confirming that โa limited number of customersโ Ivanti Connect Secure appliancesโ have been exploited by hackers using a zero-day exploit.
So critical is the issue that the Cybersecurity Infrastructure and Security Agency (CISA) has added CVE-2025-0282 to its Known Exploited Vulnerabilities catalogue and issued a legally binding and time-limited requirement for US federal agencies to apply the patch.
Ivanti Connect Secure hack: key details
The January 8th security bulletin addresses two vulnerabilities impacting Ivanti Connect Secure: Policy Secure and Neurons for ZTA gateways.
Itโs CVE-2025-0282, a stack-based buffer overflow issue, rated as critical with a 9/10 Common Vulnerabilities and Exposure (CVE) severity grade. We know that it has already been exploited by attackers.
โThreat actor activity was identified by the Integrity Checker Tool (ICT) on the same day it occurred,โ stated the Ivanti security advisory, โenabling Ivanti to respond promptly and rapidly develop a fix.โ
While Ivanti said it isย working closely with affected customers, external security partners and law enforcement agencies in response to the issue, it strongly advised โall customers to closely monitor their internal and external ICT as a part of a robust and layered approach to cybersecurity to ensure the integrity and security of the entire network infrastructureโ.
What experts say
โThe watchTowr Labs team is rapidly analysing CVE-2025-0282, the currently in-the-wild exploited Ivanti Connect Secure zero-day, and we will share those findings shortly,โ Benjamin Harris, CEO at the attack surface management provider, told us.
Adding that there is significant concern as the attack has โall the hallmarks of Advanced Persistent Threat (APT) usage of a zero-day against a mission-critical appliance,โ Harris warned โeveryone to please take this seriouslyโ.
Indeed, Harris pointed out that while there is a patch for Ivanti Connect Secure, patches for the other affected appliances are being left waiting.
โUsers of these products should not hesitate,โ Harris concluded, โthese appliances should be pulled offline until patches are available.โ
Mandiant has just published a new analysis of CVE-2025-0282 and said โit is possible that multiple actors are responsible for the creation and deploymentโ of the various malware families theyโve seen in their on-going investigations (including SPAWN, DRYHOOK and PHASEJAM).
But it also notes that โas of publishing this report, we don’t have enough data to accurately assess the number of threat actors targeting CVE-2025-0282โ.
CISA instructions to tackle Ivanti Connect Secure hack
CISA, meanwhile, warned that a cyber threat actor could exploit CVE-2025-0282 to take control of an affected system and users should take the following actions:
- Run the In-Build Integrity Checker Tool (ICT).
- Conduct threat hunt actions on any systems connected toโor recently connected toโthe affected Ivanti device.
- If threat hunting actions determine no compromise then factory reset the device and apply the patch described in the Ivanti security advisory.
- Monitor the authentication or identity management services that could be exposed.
- Continue to audit privilege level access accounts.