Critical Security Update Addresses Remotely Exploitable Vulnerabilities in Ivanti EPM
Enterprise software vendor Ivanti disclosed security updates addressing four vulnerabilities impacting its Endpoint Manager (EPM) and Neurons for MDM platforms.
Vulnerabilities in Ivanti Endpoint Manager (EPM)
The EPM release resolves three critical issues, including two remote exploitation vectors that could be leveraged by unauthenticated adversaries.
CVE-2026-18129
insecure transmission of sensitive data during external SQL connections, enabling credential interception through man-in-the-middle attacks.
CVE-2026-18125
an out-of-bounds read condition in the EPM agent that could trigger service crashes.
CVE-2026-18127
high-severity input validation flaw allowing remote attackers to manipulate filenames. This weakness could grant unauthorized control over S3 buckets used for session recording storage when exploited by authenticated threat actors.
Both issues were addressed in EPM version 2024 SU7, which also mitigates CVE-2026-18127.
Ivanti confirmed no evidence of active exploitation of these vulnerabilities at the time of disclosure.
Vulnerabilities in Ivanti Neurons for MDM
The Neurons for MDM platform received a fix for a medium-severity command-injection vulnerability that could expose sensitive data through remote attacks.
This issue, resolved in version R124 released in late June, did not qualify for a CVE identifier and lacks indicators of real-world exploitation.
The company stated these flaws do not affect other products.
Conclusion
Further details are available in the August 2026 security update documentation.
