CVE-2026-8992
Published May 22, 2026
·Updated
An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.
Affected Software
1 affected component
Ivanti Secure Access Client<22.8R6
Event History
May 22, 2026
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-8992?
The severity of CVE-2026-8992 is high with a score of 8.8.
2
How do I fix CVE-2026-8992?
To fix CVE-2026-8992, upgrade to Ivanti Secure Access Client version 22.8R6 or later.
3
What impact does CVE-2026-8992 have on systems?
CVE-2026-8992 allows a remote unauthenticated attacker to execute arbitrary code on vulnerable systems.
4
What software is affected by CVE-2026-8992?
CVE-2026-8992 affects Ivanti Secure Access Client versions prior to 22.8R6.
5
Can CVE-2026-8992 be exploited remotely?
Yes, CVE-2026-8992 can be exploited remotely without authentication.