CVE-2026-8051
Published May 12, 2026OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- evidence mentions
- 1
- Buzz score
- 11.9
Vendor/product archive
2 CVEs tagged to ivanti / virtual_traffic_manager — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the…