Database/Control plane, storage & DevOps

Ivanti Connect Secure: Stack-based buffer overflow
CVSS 9.0CVE-2025-0282Control plane, storage & DevOpsKnown exploitedcurated
Impact
Stack-based buffer overflow -> unauthenticated remote code execution
Who can reach it
Network (remote)
What to do
Control-plane: emergency patch plus factory reset
References
Related entries
- Ivanti Connect Secure: Web-component authentication bypass reaching restricted resourcesCVE-2023-46805 · Ivanti Connect SecureHigh
- Ivanti Connect Secure: Command injection in web componentsCVE-2024-21887 · Ivanti Connect SecureCritical
- Ivanti Connect Secure/ZTA: Stack-based buffer overflowCVE-2025-22457 · Ivanti Connect Secure/ZTACritical
- GitLab: unsanitized HTML in the CI job modal lets a developer-role user escalate privilegesCVE-2026-16627 · GitLab CE/EE (CI job modal HTML rendering)Critical
- Woodpecker CI: pipeline authors can pick any ServiceAccount for their build podsCVE-2026-61549 · Woodpecker CI Kubernetes backend (backend_options.kubernetes.serviceAccountName)Critical
- Jenkins Remoting: JEP-200 deserialization filter bypassed via fallback class resolution on the controllerCVE-2026-70426 · Jenkins Remoting (JEP-200 deserialization class filter, fallback resolution path)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.