Breaking
SecurityDeveloping Story

Ivanti Endpoint Manager Patches Critical Flaws

Ivanti releases updates for Endpoint Manager and Neurons for MDM addressing remotely exploitable vulnerabilities.

··2 hours ago·2 min read
a close up of a network with wires connected to it
Photo by Albert Stoynov on Unsplash

Ivanti has released security updates addressing four vulnerabilities in its Endpoint Manager (EPM) and Neurons for MDM products. The company disclosed the patches on Tuesday, with the EPM update addressing three high-severity flaws, including two that could be exploited remotely without authentication.

Among the most concerning is CVE-2026-18129, a cleartext transmission of sensitive information issue that could allow an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. The other remotely exploitable flaw, CVE-2026-18125, is an out-of-bounds read in the EPM agent that could be triggered to crash an agent service.

Three High-Severity Flaws in EPM

The EPM update, version 2024 SU7, patches three vulnerabilities. In addition to the two remotely exploitable bugs, it resolves CVE-2026-18127, an input validation weakness that allows remote attackers to control filenames. An authenticated attacker could leverage this to gain full write control over an S3 bucket configured for session recording storage.

No Evidence of Exploitation

In its advisory, Ivanti stated, “We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure.” The company noted that no other products are affected by these vulnerabilities.

Neurons for MDM Update

Ivanti Neurons for MDM received fixes for a single medium-severity command-injection vulnerability that could be exploited remotely to disclose sensitive information. The flaw was patched in version R124 of the cloud-based SaaS platform in late June. Ivanti says the issue “did not meet the criteria for reserving a CVE number” and there is no evidence that it has been exploited in the wild. The patch requires no customer action.

Key Details

  • Two EPM vulnerabilities (CVE-2026-18129 and CVE-2026-18125) are remotely exploitable without authentication.
  • The EPM update (2024 SU7) also patches CVE-2026-18127, an input validation flaw allowing filename control.
  • A single medium-severity command-injection vulnerability was patched in Neurons for MDM version R124.

What It Means for Enterprises

These patches are critical for organizations using Ivanti EPM, especially those with external SQL database connections or session recording configurations. The cleartext transmission flaw could expose credentials to network eavesdroppers, and the filename control issue could allow attackers with authenticated access to manipulate stored data. While Ivanti reports no active exploitation, the lack of public exploit details does not guarantee safety, as attackers often reverse-engineer patches to develop exploits. Enterprises should prioritize updating to EPM 2024 SU7 and review their S3 bucket configurations. For MDM customers, no action is required, but monitoring for unusual activity remains prudent. Additional information is available in Ivanti’s August 2026 security update announcement.

#ivanti#endpoint-manager#vulnerability#patch#zero-day#mdm

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories