VendorsIvantisecure_access_client22.8
Vulnerabilities

Ivanti Secure Access Client 22.8

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2026-8992
An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.
Published 2026-05-22 · Analyzed
8.8EPSS 0.006
CVE-2026-7432
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
Published 2026-05-12 · Analyzed
7.8EPSS 0.003
CVE-2026-7431
An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.
Published 2026-05-12 · Analyzed
4.4EPSS 0.002