
January 8, 2025 By Jonathan Greig
IT software vendor Ivanti said Wednesday that multiple customers have been affected by a new vulnerability being exploited by hackers.
The company released an advisory and a corresponding blog about two bugs — CVE-2025-0282 and CVE-2025-0283 — and warned that some customers have already seen CVE-2025-0282 exploited in their environments.
The bugs affect the company’s Connect Secure, Policy Secure and ZTA Gateways products — all of which are used widely across local and federal government agencies in the U.S. as well as internationally.
“We are aware of a limited number of customers’ Ivanti Connect Secure appliances which have been exploited by CVE-2025-0282 at the time of disclosure. We are not aware of these CVEs being exploited in Ivanti Policy Secure or Neurons for ZTA gateways,” Ivanti said in a statement, adding that it has not seen exploitation of CVE-2025-0283.