Ivanti Endpoint Manager Patches Critical Flaws
Ivanti releases updates for Endpoint Manager and Neurons for MDM addressing remotely exploitable vulnerabilities.
Ivanti has released security updates addressing four vulnerabilities in its Endpoint Manager (EPM) and Neurons for MDM products. The company disclosed the patches on Tuesday, with the EPM update addressing three high-severity flaws, including two that could be exploited remotely without authentication.
Among the most concerning is CVE-2026-18129, a cleartext transmission of sensitive information issue that could allow an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. The other remotely exploitable flaw, CVE-2026-18125, is an out-of-bounds read in the EPM agent that could be triggered to crash an agent service.
Three High-Severity Flaws in EPM
The EPM update, version 2024 SU7, patches three vulnerabilities. In addition to the two remotely exploitable bugs, it resolves CVE-2026-18127, an input validation weakness that allows remote attackers to control filenames. An authenticated attacker could leverage this to gain full write control over an S3 bucket configured for session recording storage.
No Evidence of Exploitation
In its advisory, Ivanti stated, “We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure.” The company noted that no other products are affected by these vulnerabilities.
Neurons for MDM Update
Ivanti Neurons for MDM received fixes for a single medium-severity command-injection vulnerability that could be exploited remotely to disclose sensitive information. The flaw was patched in version R124 of the cloud-based SaaS platform in late June. Ivanti says the issue “did not meet the criteria for reserving a CVE number” and there is no evidence that it has been exploited in the wild. The patch requires no customer action.
Key Details
- Two EPM vulnerabilities (CVE-2026-18129 and CVE-2026-18125) are remotely exploitable without authentication.
- The EPM update (2024 SU7) also patches CVE-2026-18127, an input validation flaw allowing filename control.
- A single medium-severity command-injection vulnerability was patched in Neurons for MDM version R124.
What It Means for Enterprises
These patches are critical for organizations using Ivanti EPM, especially those with external SQL database connections or session recording configurations. The cleartext transmission flaw could expose credentials to network eavesdroppers, and the filename control issue could allow attackers with authenticated access to manipulate stored data. While Ivanti reports no active exploitation, the lack of public exploit details does not guarantee safety, as attackers often reverse-engineer patches to develop exploits. Enterprises should prioritize updating to EPM 2024 SU7 and review their S3 bucket configurations. For MDM customers, no action is required, but monitoring for unusual activity remains prudent. Additional information is available in Ivanti’s August 2026 security update announcement.
Sources
- SecurityWeek Original source
- security update Also reporting
Continue Reading
England's schools recover faster from cyberattacks
Ofqual survey finds secondary schools reporting fewer incidents and quicker recovery, but training and responsibility gaps persist.
ICO gets new board and a Manchester home
The UK data protection watchdog becomes a corporate body after a leadership scandal and a move from Wilmslow to Manchester.
Zimbra Flaw Exploited Before Disclosure
Microsoft says attackers probed and exploited a Zimbra command injection flaw in the window between patch release and public disclosure.