Vulnerability intelligence
CVE-2026-39118
An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent functionality.
CVSS Score
8.4
High
EPSS — Exploit Probability
0.1%
Riskier than 2% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jun 24, 2026 · latest Jun 24, 2026
Tracked incidents
Coverage timeline
-
XM Cyber finds macOS XPC exploit that disables EDR, MDM toolswww.securityweek.com · Jun 24, 2026