CVE
CVE-2026-8111
0field notes · 1digest CVSS 8.8
Daily digests
An authenticated user on the Ivanti Endpoint Manager web console can exploit a SQL injection to achieve full remote code execution on the EPM server. You need valid credentials, but any console user will do. Given Ivanti's track record of these bugs being targeted quickly after disclosure, don't sit on this one.