Two critical vulnerabilities, CVE-2025-0282 and CVE-2025-0283, have been identified in Ivanti's Connect Secure VPN appliances, with active exploitation detected since December 2024. CVE-2025-0282 enables unauthenticated remote code execution via a buffer overflow, while CVE-2025-0283 may allow privilege escalation. These vulnerabilities pose significant risks to organizations relying on these systems for secure remote access.