- Description
- Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.
- Source
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
- NVD status
- Received
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- 3c1d8aa1-5a33-4ea4-8992-aadd6440af75
- CWE-295
- Hype score
- Not currently trending
⚠️ HIGH — CVE-2026-18129 Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a… CVSS 8.1 Full analysis → https://t.co/fFLBWbmz8A #Ivanti #CyberSecurity #InfoSec
@KaitanSecurity
11 Aug 2026
37 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Ivanti's Endpoint Manager software has disclosed critical vulnerabilities, including CVE-2026-18125, CVE-2026-18127, and CVE-2026-18129. These flaws could allow remote attackers to crash services, manipulate cloud storage, and intercept sensitive data. Organizations are urged to
@dailytechonx
11 Aug 2026
45 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes