References https://nvd.nist.gov/vuln/detail/CVE-2025-0282 https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283 https://labs.watchtowr.com/exploitation-walkthrough-and-techniques-ivanti-connect-secure-rce-cve-2025-0282/ https://cloud.google.com/blog/topics/threat-intelligence/ivanti-connect-secure-vpn-zero-day https://github.com/watchtowrlabs/CVE-2025-0282 https://unit42.paloaltonetworks.com/threat-brief-ivanti-cve-2025-0282-cve-2025-0283/ https://www.rapid7.com/blog/post/2025/01/08/etr-cve-2025-0282-ivanti-connect-secure-zero-day-exploited-in-the-wild/ https://www.wiz.io/blog/cve-2025-0282-and-cve-2025-0283-critical-ivanti-0days-exploited-in-the-wild https://www.exploit-db.com/exploits/52213 https://www.picussecurity.com/resource/resurge-malware-exploits-ivanti-connect-secure-cve-2025-0282-vulnerability
Related VulnerabilitiesPoCCVE-2026-1281: Ivanti EPMM <=12.7.0.0 - Unauthenticated Code InjectionPoCCVE-2024-1708: ConnectWise ScreenConnect <= 23.9.7 - Path TraversalPoCCVE-2015-7501: Red Hat JBoss - Insecure DeserializationPoCCVE-2019-1003030: Jenkins Pipeline Groovy Plugin <=2.63 - Insecure Deserialization英華達|全家寶 Cloud - Insecure Direct Object Referencekotaemon /check_connection 命令执行漏洞(CVE-2026-69098)PoCCVE-2026-1890: LeadConnector < 3.0.22 - Unauthenticated Arbitrary Data WritePoCCVE-2026-10520: Ivanti Sentry - OS Command InjectionPoCCVE-2026-46725: TYPO3 ceselector Extension - Insecure DeserializationIvanti Sentry存在操作系统命令注入漏洞(CVE-2026-10520)Ivanti Sentry /mics/api/v2/sentry/mics-config/handleMessage 命令执行漏洞(CVE-2026-10520)Ivanti EPMM /mifs/rs/api/v2/featureusage 命令执行漏洞(CVE-2025-4427)泛微 E-Cology /hrm/hrm_e9/orgChart/js/jquery/plugins/jqueryFileTree/connectors/jqueryFileTree.jsp 目录遍历漏洞