CISA's list that day
4 April 2025
On CISA added 1 vulnerability to its list of exploited vulnerabilities: CVE-2025-22457 in Ivanti Connect Secure, Policy Secure, and ZTA Gateways. US federal agencies must fix it by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-22457Stack-Based Buffer Overflow | Ivanti Connect Secure, Policy Secure, and ZTA Gateways | Patch this weekRansomware use; Metasploit module; EPSS 0.99 | 0.99 |