Ivanti Security Updates – 13 May 2026

Ivanti has released security updates to fix several vulnerabilities across multiple Ivanti products.

The addressed vulnerabilities could allow the attacker to obtain sensitive information, gain elevated privileges, perform SQL injection attacks, manipulate data, or conduct remote code execution attacks.

Sample of the addressed vulnerabilities:

1. Ivanti Xtraction Information Disclosure Vulnerability (CVE-2026-8043):

  • CVSS: 9.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Obtain Information

2. Ivanti Endpoint Manager SQL Injection in The Web Console Vulnerability (CVE-2026-8111):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Remote Code Execution

The affected products:

  • Ivanti Endpoint Manager (EPM).
  • Ivanti Virtual Traffic Manager.
  • Ivanti Secure Access Client.
  • Ivanti Xtraction.
Vulnerabilities
  • CVE-2026-7432
  • CVE-2026-7431
  • CVE-2026-8051
  • CVE-2026-8111
  • CVE-2026-8110
  • CVE-2026-8109
  • CVE-2026-8043
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References