Secure Access Client
Vendor:
First CVE: Oct 25, 2023 · Active for 2 years
21
Total CVEs
More Total CVEs than 94% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Secure Access Client over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2023
2 years ago
Most Recent CVE
May 22, 2026
66 days ago
CVE Severity & Scoring
Secure Access Client21 CVEs
24%
71%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local20 (95.2%)
Network1 (4.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (85.7%)
High3 (14.3%)
Unknown0 (0.0%)
User Interaction
None19 (90.5%)
Unknown0 (0.0%)
Required2 (9.5%)
Privileges Required
Low19 (90.5%)
High1 (4.8%)
None1 (4.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-8992HIGH An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. | May 22, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-7432HIGH A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM | May 12, 2026 | 7.0 | 28 | NO | NO |
CVE-2025-22454HIGH Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. | Mar 11, 2025 | 7.8 | 24 | NO | NO |
CVE-2023-34298HIGH Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installa | May 3, 2024 | 7.8 | 23 | NO | NO |
CVE-2023-38043HIGH A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, | Nov 15, 2023 | 7.8 | 23 | NO | NO |
CVE-2023-35080HIGH A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentiall | Nov 15, 2023 | 7.8 | 23 | NO | NO |
CVE-2023-46810HIGH A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root. | May 31, 2024 | 7.3 | 22 | NO | NO |
CVE-2023-38042HIGH A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM. | May 31, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-41718HIGH When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file. | Nov 15, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-38543HIGH A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, | Nov 15, 2023 | 7.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Secure Access Client
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 22.8 | 3 | 6.7 | 0.3% | 0 | 0 |
| 22.7 | 8 | 6.0 | 0.3% | 0 | 0 |
| 22.6 | 3 | 7.8 | 0.5% | 0 | 0 |
| 22.3 | 3 | 6.9 | 0.5% | 0 | 0 |
| 22.2 | 3 | 7.0 | 0.6% | 0 | 0 |