CVE-2026-8051: Ivanti Virtual Traffic Manager

High severity, CVSS 7.2. EPSS: 3% chance of exploitation in the next 30 days.

OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Affected products

  • Ivanti Virtual Traffic Manager: up to and including 22.8; version 22.9 only

Published 2026-05-12. Last modified 2026-06-17.