CVE-2025-8310: Ivanti Virtual Application Delivery Controller
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password
Affected products
- Ivanti Virtual Application Delivery Controller: before 22.9 (fixed in 22.9)
Published 2025-08-12. Last modified 2026-06-17.