Executive brief
Ivanti Secure Access Client is a software application used by employees to securely connect to corporate networks and VPNs. A security flaw in how the software verifies digital certificates allows an attacker to trick the application into trusting a malicious server. If exploited, this could allow an attacker to remotely execute unauthorized code on the user's computer, potentially leading to data theft or full system compromise.
Technical details
An improper certificate validation vulnerability (CWE-295) exists in the Ivanti Secure Access Client on Windows. The root cause is a failure to correctly validate the identity of server-side certificates during the connection process. A remote, unauthenticated attacker can exploit this by intercepting or redirecting network traffic to a malicious server. Successful exploitation requires minimal user interaction (UI:R) and can result in remote code execution (RCE) with high impact on confidentiality, integrity, and availability. Ivanti has released version 22.8R6 to address this issue.
Affected products
- Ivanti Secure Access Client before 22.8R6
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory: Ivanti released security advisory and patch information