Database/Control plane, storage & DevOps

Ivanti Endpoint Manager Mobile: Improper input validation
CVSS 7.2CVE-2026-6973Control plane, storage & DevOpsKnown exploitedcurated
Impact
Improper input validation -> authenticated admin achieves remote code execution
Who can reach it
Network (remote)
What to do
Control-plane: patch; restrict admin access to the ops network
References
Related entries
- Ivanti Endpoint Manager Mobile: Code injectionCVE-2026-1281 · Ivanti Endpoint Manager MobileCritical
- Ivanti Endpoint Manager Mobile: Code injectionCVE-2026-1340 · Ivanti Endpoint Manager MobileCritical
- Dell OpenManage Enterprise: improper privilege management lets a privileged account escalate furtherCVE-2026-70421 · Dell OpenManage Enterprise (privilege management)High
- Pandora FMS: blind SQL injection through the module parameter of the Grafana datasource endpointCVE-2026-75786 · Pandora FMS (Grafana datasource endpoint, module parameter)High
- MongoDB Server: use-after-free in query memory tracking crashes or corrupts the server processCVE-2026-82061 · MongoDB Server (query execution memory tracking)High
- Airflow FAB provider: deactivated accounts keep working through already-issued API tokensCVE-2026-82310 · Apache Airflow FAB provider (Core API token authentication)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.