Ivanti’s Patch Predicament: 5,000+ Vulnerable Devices Awaiting Attention

The Shadowserver Foundation warns over 5,000 Ivanti Connect Secure appliances are still vulnerable to CVE-2025-22457. Despite February’s fix, attacks by Chinese hackers persist. Users are urged to update, but many Pulse Connect Secure 9.x devices remain unpatched, as their support ended in December. Time to patch up before hackers get too comfortable!

Pro Dashboard

Hot Take:

**_Looks like Ivanti just pulled the classic “Oops, I did it again” move, misdiagnosing a major security flaw as a production bug. Meanwhile, a Chinese hacking group is playing whack-a-mole with over 5,000 unpatched appliances. Time to patch things up, folks!_**

Key Points:

– A vulnerability in Ivanti Connect Secure, CVE-2025-22457, allows remote code execution.
– The flaw was misdiagnosed by Ivanti as a production issue, despite ongoing in-the-wild exploitation.
– Chinese hacking group UNC5221 has been exploiting the vulnerability since March.
– Over 5,000 internet-accessible Ivanti appliances remain unpatched.
– Older Pulse Connect Secure 9.x appliances won’t receive patches due to discontinued support.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?