Ivanti released security updates to address vulnerabilities (CVE-2025-22457) in Ivanti Connect Secure, Policy Secure -& ZTA Gateways. A cyber threat actor could exploit CVE-2025-22457 to take control of an affected system.CISA has added CVE-2025-22457 to its [Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog ‘Known Exploited Vulnerabilities Catalog’).See the following resources for more guidance:* [April Security Update -| Ivanti](https://www.ivanti.com/blog/security-update-pulse-connect-secure-ivanti-connect-secure-policy-secure-and-neurons-for-zta-gateways ‘Security Update: Pulse Connect Secure, Ivanti Connect Secure, Policy Secure and Neurons for ZTA Gateways’)* [April Security Advisory Ivanti Connect Secure, Policy Secure -& ZTA Gateways (CVE-2025-22457)](https://forums.ivanti.com/s/article/April-Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-22457?language=en_US&_gl=1*y5upzl*_gcl_au*MzEyMjA5MzczLjE3NDM2ODk3ODU. ‘April Security Advisory Ivanti Connect Secure, Policy Secure & ZTA Gateways (CVE-2025-22457)’)* [Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457) -| Google Cloud Blog](https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-exploiting-critical-ivanti-vulnerability ‘Suspected China-Nexus Threat Actor Actively Exploiting Critical Ivanti Connect Secure Vulnerability (CVE-2025-22457)’)For any instances of Ivanti Connect Secure that were not updated by Feb. 28, 2025, to the latest Ivanti patch (22.7R2.6) and **all** instances of Pulse Connect Secure (EoS), Policy Secure, and ZTA Gateways, CISA urges users and administrators to implement the following actions:1. Conduct threat hunting actions: 1. Run an external Integrity Checker Tool (ICT). For more guidance, see Ivanti’s [instructions](https://www.ivanti.com/blog/enhanced-external-integrity-checking-tool-to-provide-additional-visibility-and-protection-for-customers-against-evolving-threat-actor-techniques-in-relation-to-previously-disclosed-vulnerabilities ‘Enhanced External Integrity Checking Tool to Provide Additional Visibility and Protection for Customers Against Evolving Threat Actor Techniques in Relation to Previously Disclosed Vulnerabilities’). 2. Conduct threat hunt actions on any systems connected to—or recently connected to—the affected Ivanti device.2. If threat hunting actions determine no compromise: 1. **For the highest level of confidence, conduct a factory reset.** 1. For Cloud and Virtual systems, conduct a factory reset using an external known clean image of the device. 2. Apply the patch described in Security Advisory Ivanti Connect Secure, Policy Secure -& ZTA Gateways (CVE-2025-22457). Please note that patches for Ivanti ZTA Gateways and Ivanti Policy Secure will be available April 19 and 21, respectively. Consider disconnecting vulnerable devices until patches are available. 3. Monitor the authentication or identity management services that could be exposed. 4. Continue to audit privilege level access accounts.3. If threat hunting actions determine compromise: 1. For devices that are confirmed compromised, isolate all affected instances from the network. Keep impacted devices isolated until the below guidance is completed and patches are applied. 2. Take a forensic image (including memory capture) or work with Ivanti to get a copy of the image. 3. Disconnect all compromised instances. 4. **For the highest level of confidence, conduct a factory reset.** 1. For Cloud and Virtual systems, conduct a factory reset using an external known clean image of the device. 5. Revoke and reissue any connected or exposed certificates, keys, and passwords, to include the following: 1. Reset the admin enable password. 2. Reset stored application programming interface (API) keys. 3. Reset the password of any local user defined on the gateway, including service accounts used for auth server configuration(s). 6. If domain accounts associated with the affected products have been compromised: 1. Reset passwords twice for on premise accounts, revoke Kerberos tickets, and then revoke tokens for cloud accounts in hybrid deployments. 2. For cloud joined/registered devices, disable devices in the cloud to revoke the device tokens. 7. Apply the patch described in Security Advisory Ivanti Connect Secure, Policy Secure -& ZTA Gateways (CVE-2025-22457). Please note that patches for Ivanti ZTA Gateways and Ivanti Policy Secure will be available April 19 and 21, respectively. 8. Report to CISA and Ivanti immediately.Organizations should report incidents and anomalous activity to CISA’s 24/7 Operations Center at [Report@cisa.gov](mailto:Report@cisa.gov) or (888) 282-0870.##### **Disclaimer:**The information in this report is being provided ‘as is’ for informational purposes only. CISA does not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by CISA.
Related Tags:
NAICS: 518 – Computing Infrastructure Providers
Data Processing
Web Hosting
Related Services
NAICS: 92 – Public Administration
NAICS: 922 – Justice
Public Order
Safety Activities
NAICS: 51 – Information
Blog: CISA Cybersecurity Alerts & Advisories
Exploit Public-Facing Application
Associated Indicators:


