FAIL › dossier
Connect Secure, Policy Secure, and ZTA Gateways
PRODUCT· dossier confidence 20%
Ivanti, a cybersecurity company, has experienced significant security vulnerabilities, particularly in its Connect Secure and ZTA Gateways, leading to remote code execution issues.
PROFILE
CategoryCybersecurityWhat they doConnect Secure, Policy Secure, and ZTA Gateways are cybersecurity solutions provided by Ivanti, designed to secure and manage endpoints and applications.
Websitehttps://www.ivanti.com/ ↗
SECURITY POSTURE
The company has faced multiple critical security vulnerabilities, including remote code execution flaws.
Notable failures
- CVE-2025-22457: Ivanti Connect Secure gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution, linked to ransomware.
- CVE-2025-0282: Ivanti Connect Secure, Policy Secure, and ZTA Gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution.
Patterns: Repeated unpatched edge-device RCEs
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-04-04 | CVE-2025-22457 | critical | Ivanti Connect Secure gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution, linked to ransomware. |
| 2025-01-08 | CVE-2025-0282 | critical | Ivanti Connect Secure, Policy Secure, and ZTA Gateways suffered a stack-based buffer overflow allowing unauthenticated remote code execution. |
DOSSIER SOURCES
- Company Database Search · www.edgarcompany.sec.gov
- Zscaler History, Revenue, CEO, and Zero Trust Strategy · corpdigest.com
Open questions: How has Ivanti addressed the identified security vulnerabilities? · What is the current state of Ivanti's security posture?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-24 03:45:33.207095+00:00