Critical Security Update Addresses Remotely Exploitable Vulnerabilities in Ivanti EPM

www.news4hackers.com-critical-security-update-addresses-remotely-exploitable-vulnerabilities-in-ivanti-epm-critical-security-update-addresses-remotely-exploitable-vulnerabilities-in-ivanti-epm

Enterprise software vendor Ivanti disclosed security updates addressing four vulnerabilities impacting its Endpoint Manager (EPM) and Neurons for MDM platforms.

Vulnerabilities in Ivanti Endpoint Manager (EPM)

The EPM release resolves three critical issues, including two remote exploitation vectors that could be leveraged by unauthenticated adversaries.

CVE-2026-18129

insecure transmission of sensitive data during external SQL connections, enabling credential interception through man-in-the-middle attacks.

CVE-2026-18125

an out-of-bounds read condition in the EPM agent that could trigger service crashes.

CVE-2026-18127

high-severity input validation flaw allowing remote attackers to manipulate filenames. This weakness could grant unauthorized control over S3 buckets used for session recording storage when exploited by authenticated threat actors.

Both issues were addressed in EPM version 2024 SU7, which also mitigates CVE-2026-18127.

Ivanti confirmed no evidence of active exploitation of these vulnerabilities at the time of disclosure.

Vulnerabilities in Ivanti Neurons for MDM

The Neurons for MDM platform received a fix for a medium-severity command-injection vulnerability that could expose sensitive data through remote attacks.

This issue, resolved in version R124 released in late June, did not qualify for a CVE identifier and lacks indicators of real-world exploitation.

The company stated these flaws do not affect other products.

Conclusion

Further details are available in the August 2026 security update documentation.



About Author

en_USEnglish