CVE-2026-18129
- EPSS 0.87%
- Veröffentlicht 11.08.2026 14:26:36
- Zuletzt bearbeitet 12.08.2026 05:17:42
Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.
CVE-2026-18127
- EPSS 0.39%
- Veröffentlicht 11.08.2026 14:23:45
- Zuletzt bearbeitet 11.08.2026 15:17:28
External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
CVE-2026-18125
- EPSS 0.78%
- Veröffentlicht 11.08.2026 14:18:51
- Zuletzt bearbeitet 11.08.2026 15:17:28
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
CVE-2026-8111
- EPSS 0.88%
- Veröffentlicht 12.05.2026 14:33:45
- Zuletzt bearbeitet 12.05.2026 19:17:48
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.
CVE-2026-8110
- EPSS 0.25%
- Veröffentlicht 12.05.2026 14:31:26
- Zuletzt bearbeitet 12.05.2026 19:18:08
Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.
CVE-2026-8109
- EPSS 0.7%
- Veröffentlicht 12.05.2026 14:29:10
- Zuletzt bearbeitet 12.05.2026 19:18:29
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
CVE-2026-1603
- EPSS 80.56%
- Veröffentlicht 10.02.2026 15:09:35
- Zuletzt bearbeitet 10.03.2026 13:11:30
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
CVE-2026-1602
- EPSS 0.69%
- Veröffentlicht 10.02.2026 15:07:27
- Zuletzt bearbeitet 12.02.2026 15:16:10
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
- EPSS 1.33%
- Veröffentlicht 09.12.2025 16:17:36
- Zuletzt bearbeitet 11.12.2025 17:28:03
Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.
CVE-2025-13662
- EPSS 0.56%
- Veröffentlicht 09.12.2025 16:17:36
- Zuletzt bearbeitet 11.12.2025 17:22:33
Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.