SSRF Vulnerability in Ivanti Connect Secure, Policy Secure, ZTA Gateway, and Neurons for Secure Access
CVE-2025-55139
Key Information:
- Vendor
Ivanti
- Vendor
- CVE Published:
- 9 September 2025
What is CVE-2025-55139?
A server-side request forgery (SSRF) vulnerability has been identified in multiple Ivanti products, allowing a remote authenticated attacker with admin privileges to exploit the system. This flaw enables such an attacker to enumerate and query internal services without proper restrictions. Remediation has been developed and deployed, ensuring organizations utilizing affected versions are urged to update to secure their environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Connect Secure 22.7R2.9
Neurons for Secure Access 22.8R1.4 (Fix deployed on 02-Aug-2025)
Policy Secure 22.7R1.6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved