macc /
FR EN
Demander un échange
← Retour à la console
Critique CCB · Belgique CVE-2026-8111

Ivanti has released security updates to address vulnerabilities affec…

Publié

Description

Ivanti has released security updates to fix vulnerabilities that affect several of its products. CVE-2026-8111 involves and SQL injection vulnerability in the web console component of Ivanti Endpoint Manager versions prior to 2024 SU6, with CVSS sore of 8.8. This vulnerability could allow a remote attacker to achieve remote code execution. CVE-2026-8110 is an incorrect permission assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6, with a CVSS score of 7.8. An authenticated local attacker could leverage this misconfiguration to escalate their privileges and achieve full control over the affected systems. CVE-2026-8043 addresses a critical severity vulnerability affecting Ivanti Xtraction before version 2026.2, with a CVSS score of 9.6. The vulnerability involves exte