Ivanti Endpoint Manager Patches Critical Flaws
Ivanti releases updates for Endpoint Manager and Neurons for MDM addressing remotely exploitable vulnerabilities.
Ivanti has released security updates addressing four vulnerabilities in its Endpoint Manager (EPM) and Neurons for MDM products. The company disclosed the patches on Tuesday, with the EPM update addressing three high-severity flaws, including two that could be exploited remotely without authentication.
Among the most concerning is CVE-2026-18129, a cleartext transmission of sensitive information issue that could allow an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. The other remotely exploitable flaw, CVE-2026-18125, is an out-of-bounds read in the EPM agent that could be triggered to crash an agent service.
Three High-Severity Flaws in EPM
The EPM update, version 2024 SU7, patches three vulnerabilities. In addition to the two remotely exploitable bugs, it resolves CVE-2026-18127, an input validation weakness that allows remote attackers to control filenames. An authenticated attacker could leverage this to gain full write control over an S3 bucket configured for session recording storage.
No Evidence of Exploitation
In its advisory, Ivanti stated, “We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure.” The company noted that no other products are affected by these vulnerabilities.
Neurons for MDM Update
Ivanti Neurons for MDM received fixes for a single medium-severity command-injection vulnerability that could be exploited remotely to disclose sensitive information. The flaw was patched in version R124 of the cloud-based SaaS platform in late June. Ivanti says the issue “did not meet the criteria for reserving a CVE number” and there is no evidence that it has been exploited in the wild. The patch requires no customer action.
Key Details
- Two EPM vulnerabilities (CVE-2026-18129 and CVE-2026-18125) are remotely exploitable without authentication.
- The EPM update (2024 SU7) also patches CVE-2026-18127, an input validation flaw allowing filename control.
- A single medium-severity command-injection vulnerability was patched in Neurons for MDM version R124.
What It Means for Enterprises
These patches are critical for organizations using Ivanti EPM, especially those with external SQL database connections or session recording configurations. The cleartext transmission flaw could expose credentials to network eavesdroppers, and the filename control issue could allow attackers with authenticated access to manipulate stored data. While Ivanti reports no active exploitation, the lack of public exploit details does not guarantee safety, as attackers often reverse-engineer patches to develop exploits. Enterprises should prioritize updating to EPM 2024 SU7 and review their S3 bucket configurations. For MDM customers, no action is required, but monitoring for unusual activity remains prudent. Additional information is available in Ivanti’s August 2026 security update announcement.
Sources
- SecurityWeek Original source
- security update Also reporting
Continue Reading
VMware vCenter Flaw Exploited for Persistent Access
Attacks exploiting CVE-2026-59310 target hundreds of victims, deploying reverse_ssh for persistent access.
Chipmakers Patch Over 80 Bugs, Including Severe Flaws
Intel and AMD release combined patches for more than 80 vulnerabilities, including high-severity issues in processors and software.
Industrial Patch Tuesday: Critical Gaps Closed in Siemens, Schneider, Phoenix
August 2026 ICS Patch Tuesday advisories from Siemens, Schneider Electric, Phoenix Contact address critical vulnerabilities, including a maximum-severity flaw in Siemens IoT devices.