CVE-2025-5468: Ivanti Connect Secure
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files on disk.
Affected products
- Ivanti Connect Secure: before 22.7 (fixed in 22.7); version 22.7 only
- Ivanti Neurons For Secure Access: before 22.8 (fixed in 22.8); version 22.8 only
- Ivanti Policy Secure: before 22.7 (fixed in 22.7); version 22.7 only
- Ivanti Zero Trust Access Gateway: version 22.8 only
Published 2025-08-12. Last modified 2026-06-17.