CVE-2026-8992: High severity Ivanti Secure Access Client vulnerability
Published May 22, 2026
·Updated
An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.
Affected Software
9 affected components
Ivanti Secure Access Client<22.8R6
All of the following
Any of the following
Ivanti Secure Access Client<=22.7
Ivanti Secure Access Client=22.8
Ivanti Secure Access Client=22.8-r1
Ivanti Secure Access Client=22.8-r2
Ivanti Secure Access Client=22.8-r3
Ivanti Secure Access Client=22.8-r4
Ivanti Secure Access Client=22.8-r5
Microsoft Windows
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Secure Access Clientto a version that resolves this vulnerability.Fixed in 22.8R6
Event History
May 22, 2026
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 27, 58520
Event
via FIRST·11:25 PM
Frequently Asked Questions
1
What is the severity of CVE-2026-8992?
The severity of CVE-2026-8992 is high with a score of 8.8.
2
How do I fix CVE-2026-8992?
To fix CVE-2026-8992, upgrade to Ivanti Secure Access Client version 22.8R6 or later.
3
What impact does CVE-2026-8992 have on systems?
CVE-2026-8992 allows a remote unauthenticated attacker to execute arbitrary code on vulnerable systems.
4
What software is affected by CVE-2026-8992?
CVE-2026-8992 affects Ivanti Secure Access Client versions prior to 22.8R6.
5
Can CVE-2026-8992 be exploited remotely?
Yes, CVE-2026-8992 can be exploited remotely without authentication.