- Description
- External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.
- Source
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 7.7
- Impact score
- 4
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- Severity
- HIGH
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
- CWE-73
- Hype score
- Not currently trending
⚠️ HIGH — CVE-2026-18127 External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authentic… CVSS 7.7 Full analysis → https://t.co/rwur4rMd8T #Ivanti #CyberSecurity #InfoSec
@KaitanSecurity
11 Aug 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ivanti's Endpoint Manager software has disclosed critical vulnerabilities, including CVE-2026-18125, CVE-2026-18127, and CVE-2026-18129. These flaws could allow remote attackers to crash services, manipulate cloud storage, and intercept sensitive data. Organizations are urged to
@dailytechonx
11 Aug 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes