CVE-2026-8110
Ivanti has released security updates to fix vulnerabilities that affect several of its products. CVE-2026-8111 involves and SQL injection vulnerability in the web console component of Ivanti Endpoint Manager versions prior to 2024 SU6, with CVSS sore of 8.8. This vulnerability could allow a remote attacker to achieve remote code execution. CVE-2026-8110 is an incorrect permission assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6, with a CVSS score of 7.8. An authenticated local attacker could leverage this misconfiguration to escalate their privileges and achieve full control over the affected systems. CVE-2026-8043 addresses a critical severity vulnerability affecting Ivanti Xtraction before version 2026.2, with a CVSS score of 9.6. The vulnerability involves external control of a file name, which allows a remote authenticated attacker to read files and write arbitrary HTML files to a web directory. This results in information disclosure and may facilitate client-side attacks against users accessing the affected web content. CVE-2026-8051 affects Ivanti Traffic Manager versions prior to 22.9r4; it addresses a high-severity vulnerability with a CVSS score of 7.2. This vulnerability could allow a remote attacker who has authenticated with admin privileges to perform OS command injection, resulting in remote code execution. CVE-2026-7432 involves race condition in Ivanti Secure Access Client prior to version 22.8R6, which addresses a high severity vulnerability, with a CVSS score of 7.8. A race condition occurs when concurrent execution using shared resources is not properly synchronized, which in this case could allow a locally authenticated attacker to escalate privileges to SYSTEM level.
EPSS 0.03% · 7.8th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ivanti | Ivanti Xtraction 2026.1 and prior | |
| Ivanti | Ivanti Virtual Traffic Manager (vTM) (vADC) 22.9r3 and prior | |
| Ivanti | Ivanti Endpoint Manager (EPM) 2024 SU5 and prior | |
| Ivanti | Ivanti Secure Access Client (Windows) 22.8R5 and prior |
Timeline
- May 12, 2026 PoC Published
- May 12, 2026 CVE Published
- May 13, 2026 EPSS Score
- May 13, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
References
- https://ccb.belgium.be/advisories/warning-ivanti-has-released-security-updates-address-vulnerabilities-affecting-several advisory
- https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-EPM-May-2026 vendor
- https://hub.ivanti.com/s/article/Security-Advisory---Ivanti-Xtraction-CVE-2026-8043 vendor
- https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Virtual-Traffic-Manager-vTM-CVE-2026-8051 vendor
- https://hub.ivanti.com/s/article/May-2026-Security-Advisory-Ivanti-Secure-Access-Client-CVE-2026-7431-CVE-2026-7432 vendor
- https://nvd.nist.gov/vuln/detail/CVE-2026-8111 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-8110 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-8043 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-8051 technical
- https://nvd.nist.gov/vuln/detail/CVE-2026-7432 technical