CVE-2025-0282, affecting Ivanti Connect Secure, was exploited in the wild from January 2025. A second vulnerability, CVE-2025-22457, followed in the same product line.
A VPN Concentrator Is A Privileged Position
The device exists to authenticate remote users and place them inside the network. Compromising it means occupying the point through which trusted access is granted — able to observe credentials as they arrive and to reach whatever the network permits an authenticated user to reach.
It is the identity-boundary argument this corpus files repeatedly, expressed as hardware rather than as a help desk. At 25-0512 the boundary was a person who could be persuaded; here it is an appliance with a parser.
Two In One Product Line In One Quarter
Consecutive exploited vulnerabilities in the same product within months is the pattern also recorded at 25-0624. It suggests a codebase receiving concentrated research attention — which happens precisely because the first finding demonstrated the category was productive.
For a defender that has an unwelcome implication: a vendor whose product was exploited recently is more likely, not less, to be exploited again soon. The disclosure that prompts patching also advertises where to look.
And Remediation Does Not End At The Update
As at 25-0723, an appliance compromise leaves questions the patch does not answer: whether credentials passing through were captured, whether persistence was established in the appliance image, whether sessions issued during the exposure window remain valid.
Vendor guidance for these events routinely includes factory reset and credential rotation. How often that is completed is not something this desk can measure, and nobody publishes it.
Compiled from vendor advisories and public research, listed below. Victim counts are not established. Corrections: corrections@forensicpost.com.