CISA's list that day

4 April 2025

On CISA added 1 vulnerability to its list of exploited vulnerabilities: CVE-2025-22457 in Ivanti Connect Secure, Policy Secure, and ZTA Gateways. US federal agencies must fix it by .

Added that day

Added that day
VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2025-22457Stack-Based Buffer OverflowIvanti Connect Secure, Policy Secure, and ZTA GatewaysPatch this weekRansomware use; Metasploit module; EPSS 0.990.99

Other changes that day

  1. CVE-2022-27925 Synacor Zimbra Collaboration Suite (ZCS)Ransomware use: Unknown to Known.
  2. CVE-2022-37042 Synacor Zimbra Collaboration Suite (ZCS)Ransomware use: Unknown to Known.