CVE-2025-66374: Cyberark Endpoint Privilege Manager

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through policy elevation of an Administration task.

Affected products

  • Cyberark Endpoint Privilege Manager: up to and including 25.10.0

Published 2026-02-03. Last modified 2026-06-17.