CVE-2025-8310: Ivanti Virtual Application Delivery Controller

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password

Affected products

  • Ivanti Virtual Application Delivery Controller: before 22.9 (fixed in 22.9)

Published 2025-08-12. Last modified 2026-06-17.