CVE-2024-7593: Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-09-24. EPSS: 100% chance of exploitation in the next 30 days.
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
Affected products
- Ivanti Virtual Traffic Manager: version 22.2 only; version 22.3 only; version 22.5 only; version 22.6 only; version 22.7 only
Published 2024-08-13. Last modified 2026-06-17.