Ivanti Security Update – 24 May 2026

Ivanti has released a security update to fix a vulnerability affecting Ivanti Secure Access Client (Windows) versions 22.8R5 and prior.

The addressed vulnerability could allow the remote unauthenticated attacker to execute arbitrary code on the affected products.

The addressed vulnerability:

Ivanti Secure Access Client Improper Certificate Validation Vulnerability (CVE- 2026-8992):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Remote Code Execution
Vulnerabilities

CVE-2026-8992

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References