Ivanti Vulnerabilities and Affected Products
Vulnerabilities associated with Secure Access Client.
Products
Clear product- Avalanche94 vulnerabilities
- Endpoint Manager71 vulnerabilities
- Connect Secure62 vulnerabilities
- Policy Secure52 vulnerabilities
- endpoint_manager45 vulnerabilities
- EPM33 vulnerabilities
- connect_secure24 vulnerabilities
- policy_secure20 vulnerabilities
- Endpoint Manager Mobile18 vulnerabilities
- Secure Access Client15 vulnerabilities
- ZTA Gateway15 vulnerabilities
- Connect Secure and Policy Secure14 vulnerabilities
- Neurons for Secure Access13 vulnerabilities
- EPMM11 vulnerabilities
- Workspace Control10 vulnerabilities
- automation8 vulnerabilities
- endpoint_manager_mobile8 vulnerabilities
- Endpoint Manager Mobile (EPMM)7 vulnerabilities
- Pulse Connect Secure7 vulnerabilities
- CSA (Cloud Services Appliance)6 vulnerabilities
- endpoint_manager_cloud_services_appliance6 vulnerabilities
- secure_access_client6 vulnerabilities
- Sentry6 vulnerabilities
- Cloud Services Application5 vulnerabilities
- Endpoint Manager (EPM)5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-8992HIGH | Generated title:Ivanti Secure Access Client Improper Certificate Validation Remote Code ExecutionAn improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. CWE-295May 22, 2026 | CVSS8.8v3.1 | EPSS0.564% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7432HIGH | Generated title:Ivanti Secure Access Client Race Condition Privilege EscalationA race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM CWE-362May 12, 2026 | CVSS7.8v3.1 | EPSS0.284% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-7431MEDIUM | Generated title:Ivanti Secure Access Client Incorrect Permission Assignment for Critical ResourceAn incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section. CWE-732May 12, 2026 | CVSS4.4v3.1 | EPSS0.176% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-22454HIGH | Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. CWE-732Mar 11, 2025 | CVSS7.8v3.1 | EPSS0.299% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-13813HIGH | Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files. CWE-732Feb 11, 2025 | CVSS7.1v3.1 | EPSS0.208% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-29211MEDIUM | A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files. CWE-362Nov 13, 2024 | CVSS4.7v3.1 | EPSS0.296% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-38654MEDIUM | Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service. CWE-125Nov 13, 2024 | CVSS4.4v3.0 | EPSS0.28% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-37398HIGH | Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. Nov 13, 2024 | CVSS7.8v3.1 | EPSS0.322% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-7571HIGH | Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. CWE-267Nov 12, 2024 | CVSS7.8v3.1 | EPSS0.262% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9843MEDIUM | A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service. | CVSS5.0v3.1 | EPSS0.254% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-9842HIGH | Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders. | CVSS7.3v3.1 | EPSS0.21% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-8539HIGH | Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files. CWE-267Nov 12, 2024 | CVSS7.1v3.1 | EPSS0.215% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-38042HIGH | A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM. CWE-250May 31, 2024 | CVSS7.8v3.0 | EPSS0.343% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-35080HIGH | A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure. CWE-276Nov 14, 2023 | CVSS7.8v3.1 | EPSS0.713% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-38041HIGH | A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system. CWE-367Oct 25, 2023 | CVSS7.0v3.1 | EPSS0.672% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |