PatchDay Alert

CVE

CVE-2026-8111

0field notes · 1digest CVSS 8.8


Daily digests

An authenticated user on the Ivanti Endpoint Manager web console can exploit a SQL injection to achieve full remote code execution on the EPM server. You need valid credentials, but any console user will do. Given Ivanti's track record of these bugs being targeted quickly after disclosure, don't sit on this one.

Get the digest

Free. Weekday mornings. Plain English CVE triage.

Check your inbox to confirm.