AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18129

HIGH · CVSS 8.1 EPSS 0.87%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Ivanti Endpoint Manager versions prior to 2024 SU7 are vulnerable to a high-severity issue that allows remote unauthenticated attackers to intercept sensitive information, specifically credentials for external SQL connections, due to cleartext transmission. This vulnerability poses a significant risk for organizations using affected versions, as it could lead to unauthorized access to databases and sensitive data. Organizations utilizing Ivanti Endpoint Manager should prioritize applying the latest updates to mitigate this risk.

CVE
CVE-2026-18129
Severity
HIGH
CVSS
8.1
EPSS
0.87%
Ivanti

Original NVD Description

Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.