CVE-2026-8992
Ivanti Secure Access Client vulnerability analysis and mitigation

Overview

CVE-2026-8992 is an improper certificate validation vulnerability in Ivanti Secure Access Client that allows a remote unauthenticated attacker to execute arbitrary code. It affects all versions of Ivanti Secure Access Client before 22.8R6, including versions 22.7 and earlier, and 22.8 through 22.8R5. The vulnerability was published on May 22, 2026, with a patch made available shortly after. It carries a CVSS v3.1 base score of 8.8 (High) (Feedly, ENISA EUVD).

Technical details

The root cause is classified as CWE-295 (Improper Certificate Validation), meaning the client software fails to properly verify the authenticity or integrity of certificates presented during network communications. This flaw enables a network-based attacker to perform a man-in-the-middle or rogue certificate authority attack (CAPEC-459, CAPEC-475), intercepting or spoofing trusted connections to deliver and execute malicious code on the victim's system. Exploitation requires user interaction — such as a user clicking a link or accepting a connection — but no authentication or elevated privileges are needed on the attacker's side (Feedly, ENISA EUVD).

Impact

Successful exploitation grants a remote unauthenticated attacker the ability to execute arbitrary code on systems running vulnerable versions of Ivanti Secure Access Client, resulting in high impact to confidentiality, integrity, and availability. An attacker could fully compromise the affected endpoint, potentially accessing sensitive VPN credentials, session tokens, or corporate network resources, and use the foothold for lateral movement within the organization. The scope is limited to the affected client system, but the nature of VPN client software means compromised endpoints may have privileged access to internal networks (Feedly).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, though it was referenced in a CISA vulnerability bulletin (CISA Bulletin). The EPSS score is approximately 0.117%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify targets running Ivanti Secure Access Client versions prior to 22.8R6 — these are typically corporate VPN users. Tools like Shodan or internal asset inventories can help identify exposed endpoints.
  2. Set up rogue infrastructure: Deploy a malicious server with a fraudulent or self-signed certificate that the vulnerable client will fail to properly validate, simulating a legitimate Ivanti gateway or update server.
  3. Position for interception: Conduct a man-in-the-middle attack on the network path between the victim and the legitimate Ivanti server (e.g., via ARP spoofing, DNS poisoning, or rogue Wi-Fi access point), or craft a phishing link directing the victim to the attacker-controlled server.
  4. Trigger user interaction: Lure the target user into initiating a VPN connection or clicking a crafted link that causes the Secure Access Client to connect to the attacker's server. The client accepts the fraudulent certificate due to the improper validation flaw.
  5. Deliver and execute malicious payload: Once the client trusts the rogue server, serve a malicious update or response payload that results in arbitrary code execution on the victim's machine with the privileges of the Secure Access Client process (Feedly, ENISA EUVD).

Indicators of compromise

  • Network: Unexpected TLS connections from Ivanti Secure Access Client processes to unknown or unrecognized IP addresses/domains; certificate mismatches or self-signed certificates observed in TLS handshakes with Ivanti gateway endpoints; DNS queries for lookalike Ivanti domains.
  • Process: Unusual child processes spawned by the Ivanti Secure Access Client process (e.g., cmd.exe, powershell.exe, bash, curl, wget); unexpected network connections initiated by the client process to non-corporate IPs.
  • Logs: Client-side VPN logs showing connections to unrecognized gateway addresses; certificate validation warnings or errors suppressed in application logs; authentication events from unexpected source IPs in VPN gateway logs.
  • File System: New or modified executables, scripts, or configuration files in the Ivanti Secure Access Client installation directory; unexpected scheduled tasks or startup entries created around the time of a VPN connection event.

Mitigation and workarounds

Ivanti has released version 22.8R6 of Ivanti Secure Access Client, which addresses this vulnerability. Organizations should upgrade all client installations to 22.8R6 or later as the primary remediation (Ivanti Advisory). For systems that cannot be immediately patched, implement network controls to restrict client connections to only trusted and verified gateway addresses, and educate users to avoid clicking suspicious links or accepting unexpected VPN connection prompts. Monitoring for anomalous certificate usage and unexpected outbound connections from VPN client processes is also recommended as a compensating control (Feedly).

Community reactions

The Swiss National Cyber Security Centre (NCSC-CH) flagged CVE-2026-8992 in a brief published on May 30, 2026, alongside a local privilege escalation issue, recommending users update Ivanti Secure Access Client promptly (NCSC-CH Brief). CISA included the vulnerability in its weekly vulnerability bulletin (SB26-145) (CISA Bulletin). No significant independent researcher commentary or social media discussion has been observed beyond standard vulnerability aggregator coverage.

Additional resources


SourceThis report was generated using AI

Related Ivanti Secure Access Client vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-8992HIGH8.8
  • Ivanti Secure Access Client logoIvanti Secure Access Client
  • cpe:2.3:a:ivanti:secure_access_client
NoYesMay 22, 2026
CVE-2025-22454HIGH7.8
  • Ivanti Secure Access Client logoIvanti Secure Access Client
  • cpe:2.3:a:ivanti:secure_access_client
NoYesMar 11, 2025
CVE-2024-13813HIGH7.1
  • Ivanti Secure Access Client logoIvanti Secure Access Client
  • cpe:2.3:a:ivanti:secure_access_client
NoYesFeb 11, 2025
CVE-2026-7432HIGH7
  • Ivanti Secure Access Client logoIvanti Secure Access Client
  • cpe:2.3:a:ivanti:secure_access_client
NoYesMay 12, 2026
CVE-2026-7431MEDIUM4.4
  • Ivanti Secure Access Client logoIvanti Secure Access Client
  • cpe:2.3:a:ivanti:secure_access_client
NoYesMay 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management