← Vulnerability feed

Vulnerability record · CVE-2026-8992 · published 22 May 2026

CVE-2026-8992: Ivanti secure access client improper certificate validation vulnerability

Ivanti · Secure Access Client

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.

8.8 CVSS 3.1 High EPSS 1.2% · top 33.9% CWE-295 · Improper certificate validation
8.8CVSS 3.1 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
23 Jul 2026Last modified by NVD

Description

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-8992 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2025-22454Ivanti secure access client incorrect permission assignment vulnerabilityInsufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privilege…EPSS 0.30%7.8CVE-2024-37398Ivanti secure access client vulnerabilityInsufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.EPSS 0.32%7.8CVE-2024-7571Ivanti secure access client vulnerabilityIncorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.EPSS 0.26%7.8CVE-2023-38042Ivanti secure access client execution with unnecessary privileges vulnerabilityA local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.EPSS 0.34%7.8CVE-2023-34298Ivanti pulse secure desktop client path traversal vulnerabilityPulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate …EPSS 0.97%7.8CVE-2023-38543Ivanti secure access client allocation without limits vulnerabilityA vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to explo…EPSS 0.37%7.8CVE-2023-41718Ivanti secure access client incorrect default permissions vulnerabilityWhen a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having cont…EPSS 0.45%7.8CVE-2023-35080Ivanti secure access client incorrect default permissions vulnerabilityA vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulne…EPSS 0.71%

Source: NIST National Vulnerability Database (record CVE-2026-8992), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.