Ivanti disclosed a critical vulnerability (CVE-2025-22457) affecting Ivanti Connect Secure, Pulse Connect Secure, and other gateway products. The stack-based buffer overflow flaw enables remote, unauthenticated attackers to execute arbitrary code. Initially seen as a low-risk bug and patched in February 2025, it has been actively exploited since mid-March by suspected Chinese threat actors deploying TRAILBLAZE and BRUSHFIRE malware. Ivanti patched Connect Secure in v22.7R2.6, and organizations must update or migrate unsupported systems immediately.