CVE-2026-8992

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ivanti:secure_access_client:*:*:*:*:*:*:*:*
cpe:2.3:a:ivanti:secure_access_client:22.8:-:*:*:*:*:*:*
cpe:2.3:a:ivanti:secure_access_client:22.8:r1:*:*:*:*:*:*
cpe:2.3:a:ivanti:secure_access_client:22.8:r2:*:*:*:*:*:*
cpe:2.3:a:ivanti:secure_access_client:22.8:r3:*:*:*:*:*:*
cpe:2.3:a:ivanti:secure_access_client:22.8:r4:*:*:*:*:*:*
cpe:2.3:a:ivanti:secure_access_client:22.8:r5:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

22 May 2026, 17:50

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-22 15:16

Updated : 2026-05-22 17:50


NVD link : CVE-2026-8992

Mitre link : CVE-2026-8992

CVE.ORG link : CVE-2026-8992


JSON object : View

Products Affected

microsoft

  • windows

ivanti

  • secure_access_client
CWE
CWE-295

Improper Certificate Validation