Database/Control plane, storage & DevOps

Ivanti Connect Secure/ZTA: Stack-based buffer overflow
CVSS 9.0CVE-2025-22457Control plane, storage & DevOpsKnown exploitedcurated
Impact
Stack-based buffer overflow -> unauthenticated RCE, exploited by a China-nexus actor
Who can reach it
Network (remote)
What to do
Control-plane: patch; assume compromise
References
Related entries
- GitLab: unsanitized HTML in the CI job modal lets a developer-role user escalate privilegesCVE-2026-16627 · GitLab CE/EE (CI job modal HTML rendering)Critical
- Woodpecker CI: pipeline authors can pick any ServiceAccount for their build podsCVE-2026-61549 · Woodpecker CI Kubernetes backend (backend_options.kubernetes.serviceAccountName)Critical
- Jenkins Remoting: JEP-200 deserialization filter bypassed via fallback class resolution on the controllerCVE-2026-70426 · Jenkins Remoting (JEP-200 deserialization class filter, fallback resolution path)Critical
- Crossplane package manager (cosign signature verification via ImageConfig): SUPPLY CHAIN, TIME-OF-CHECK TO TIME-OF-USENCVD-2026-055-crossplane-package-manager-cosig · Crossplane package manager (cosign signature verification via ImageConfig)Critical
- Ceph CephX: malleable, unauthenticated tickets let a low-privilege key be forged into Manager, MDS or OSD accessCVE-2025-30156 · Ceph CephX authentication protocol (unauthenticated AES-128-CBC ticket encryption)High
- Ceph CephX (authentication protocol): A tenant holding one low-privilege CephX client key ends up with cluster-wideNCVD-2025-016-ceph-cephx-authentication-protoc · Ceph CephX (authentication protocol)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.