logo

Ivanti Patches Multiple Vulnerabilities in Secure Access, Xtraction, vTM and Endpoint Manager

ID: d8734c42-5a34-5914-b54c-b99979c4b089

STIX ID: report--d8734c42-5a34-5914-b54c-b99979c4b089

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Guru Baran

...
...

Ivanti's May 2026 Patch Tuesday advisory discloses multiple vulnerabilities in Secure Access Client, Xtraction, Virtual Traffic Manager, and Endpoint Manager — ranging from local privilege escalation and sensitive log/credential exposure to path traversal enabling file writes, OS command injection (admin-authenticated), and a SQL injection in the EPM web console that can lead to remote code execution; Ivanti says there is no known in-the-wild exploitation and recommends immediate patching, noting several flaws were discovered using AI-assisted review.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.