
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-8992 is an improper certificate validation vulnerability in Ivanti Secure Access Client that allows a remote unauthenticated attacker to execute arbitrary code. It affects all versions of Ivanti Secure Access Client before 22.8R6, including versions 22.7 and earlier, and 22.8 through 22.8R5. The vulnerability was published on May 22, 2026, with a patch made available shortly after. It carries a CVSS v3.1 base score of 8.8 (High) (Feedly, ENISA EUVD).
The root cause is classified as CWE-295 (Improper Certificate Validation), meaning the client software fails to properly verify the authenticity or integrity of certificates presented during network communications. This flaw enables a network-based attacker to perform a man-in-the-middle or rogue certificate authority attack (CAPEC-459, CAPEC-475), intercepting or spoofing trusted connections to deliver and execute malicious code on the victim's system. Exploitation requires user interaction — such as a user clicking a link or accepting a connection — but no authentication or elevated privileges are needed on the attacker's side (Feedly, ENISA EUVD).
Successful exploitation grants a remote unauthenticated attacker the ability to execute arbitrary code on systems running vulnerable versions of Ivanti Secure Access Client, resulting in high impact to confidentiality, integrity, and availability. An attacker could fully compromise the affected endpoint, potentially accessing sensitive VPN credentials, session tokens, or corporate network resources, and use the foothold for lateral movement within the organization. The scope is limited to the affected client system, but the nature of VPN client software means compromised endpoints may have privileged access to internal networks (Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, though it was referenced in a CISA vulnerability bulletin (CISA Bulletin). The EPSS score is approximately 0.117%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported.
cmd.exe, powershell.exe, bash, curl, wget); unexpected network connections initiated by the client process to non-corporate IPs.Ivanti has released version 22.8R6 of Ivanti Secure Access Client, which addresses this vulnerability. Organizations should upgrade all client installations to 22.8R6 or later as the primary remediation (Ivanti Advisory). For systems that cannot be immediately patched, implement network controls to restrict client connections to only trusted and verified gateway addresses, and educate users to avoid clicking suspicious links or accepting unexpected VPN connection prompts. Monitoring for anomalous certificate usage and unexpected outbound connections from VPN client processes is also recommended as a compensating control (Feedly).
The Swiss National Cyber Security Centre (NCSC-CH) flagged CVE-2026-8992 in a brief published on May 30, 2026, alongside a local privilege escalation issue, recommending users update Ivanti Secure Access Client promptly (NCSC-CH Brief). CISA included the vulnerability in its weekly vulnerability bulletin (SB26-145) (CISA Bulletin). No significant independent researcher commentary or social media discussion has been observed beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."