Ivanti Releases September 2025 Security Updates
Updates address vulnerabilities in Connect Secure, Policy Secure, ZTA Gateways, and Neurons for Secure Access
Summary
Updates address vulnerabilities in Connect Secure, Policy Secure, ZTA Gateways, and Neurons for Secure Access
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Ivanti has released a security advisory addressing 11 vulnerabilities affecting Connect Secure, Policy Secure, ZTA Gateways and Neurons for Secure Access.
- CVE-2025-55145 - Missing Authorisation vulnerability - CVSSv3 score: 8.9
- CVE-2025-55147 - Cross Site Request Forgery vulnerability - CVSSv3 score: 8.8
- CVE-2025-55141 - Missing Authorisation vulnerability - CVSSv3 score: 8.8
- CVE-2025-55142 - Missing Authorisation vulnerability - CVSSv3 score: 8.8
- CVE-2025-55148 - Missing Authorisation vulnerability - CVSSv3 score: 7.6
Updates address six other medium severity vulnerabilities.
Remediation advice
Affected organisations are encouraged to review Ivanti's September Security Advisory Ivanti Connect Secure, Policy Secure, ZTA Gateways and Neurons for Secure Access (Multiple CVEs) advisory and apply the relevant updates as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 10 September 2025 11:12 am