« Back to list

Ivanti

Ivanti Virtual Traffic Manager: vulnerabilities and CVEs

Ivanti Virtual Traffic Manager has 2 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 1 are listed by CISA as actively exploited.

CVEs2
Last 12 months1
Critical1
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2024-7593Critical (9.8)100%⚠ Active exploitationAug 13, 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-8051High (7.2)3.0%—May 12, 2026
OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-7593Critical (9.8)100%⚠ Active exploitationAug 13, 2024
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1078 Valid Accounts1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Ivanti