Ivanti Patches Multiple Vulnerabilities in Secure Access, Xtraction, vTM and Endpoint Manager
ID: d8734c42-5a34-5914-b54c-b99979c4b089
STIX ID: report--d8734c42-5a34-5914-b54c-b99979c4b089
Feed Name: cybersecurityNews.com
Ivanti's May 2026 Patch Tuesday advisory discloses multiple vulnerabilities in Secure Access Client, Xtraction, Virtual Traffic Manager, and Endpoint Manager — ranging from local privilege escalation and sensitive log/credential exposure to path traversal enabling file writes, OS command injection (admin-authenticated), and a SQL injection in the EPM web console that can lead to remote code execution; Ivanti says there is no known in-the-wild exploitation and recommends immediate patching, noting several flaws were discovered using AI-assisted review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
