CVE-2024-7593: Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2024-09-24. EPSS: 100% chance of exploitation in the next 30 days.

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

Affected products

  • Ivanti Virtual Traffic Manager: version 22.2 only; version 22.3 only; version 22.5 only; version 22.6 only; version 22.7 only

Published 2024-08-13. Last modified 2026-06-17.