Ivanti Patches Three High-Severity Flaws in Endpoint Manager That Attackers Could Hit Remotely

Two of the bugs needed no password to exploit. Ivanti says no customers were hit before the fixes landed.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
An Ivanti Endpoint Manager dashboard on a monitor showing system administration controls, with security alerts and patch notifications displayed, network diagra
Share

Key points

  • Ivanti patched three high-severity vulnerabilities in Endpoint Manager (EPM) on Tuesday, August 2026, fixing all three in version 2024 SU7.
  • Two of the three flaws could be exploited by a remote attacker with no login credentials required.
  • A fourth, medium-severity flaw in Ivanti Neurons for MDM was fixed in late June 2026 in version R124 and requires no action from customers.
  • Ivanti says it has no evidence any of the four vulnerabilities were exploited before patches were released.

Ivanti released security fixes Tuesday for four vulnerabilities across two products. Three are rated high severity, and two of those need no username or password to trigger.

All three high-severity bugs sit inside Ivanti Endpoint Manager (EPM), software IT teams use to control and monitor devices on a corporate network. The fixes are bundled into EPM version 2024 SU7. We covered Ivanti's two-product patch round on 15 July 2026, when twelve Fortinet products and two Ivanti tools received fixes on the same day.

How bad are these flaws?

The two no-login-required bugs are what defenders should focus on first.

CVE-2026-18129 is a cleartext transmission flaw: the software was sending credentials for external SQL database connections across the network in plain, readable text. An attacker positioned between two systems, a technique called a man-in-the-middle attack, could silently capture those credentials.

CVE-2026-18125 is an out-of-bounds read bug inside the EPM agent, a small background program that runs on managed devices. Triggering it crashes that agent service, knocking out device management on the affected machine.

CVE-2026-18127 does require a valid login. Once inside, an attacker can manipulate filenames to gain full write access to an S3 bucket, a cloud storage container, configured to record user sessions. Serious post-login escalation, but the authentication bar matters.

CVE ID Severity Needs Login? What it does
CVE-2026-18129 High No Leaks database credentials over the network
CVE-2026-18125 High No Crashes the EPM agent service
CVE-2026-18127 High Yes Grants full write access to cloud session-recording storage
(no CVE assigned) Medium No Command injection in Neurons for MDM, fixed in R124

Ivanti says the Neurons for MDM flaw didn't meet the threshold for a CVE number. It can be exploited remotely to expose sensitive information.

Should IT teams act urgently?

Yes, on the two no-login flaws. Ivanti told customers it has no evidence of exploitation before disclosure. That window narrows the longer organisations wait.

Admins running EPM should update to version 2024 SU7 as soon as their change-management process allows. Customers using Ivanti Neurons for MDM, a cloud-based mobile device management service, got the fix automatically in late June in version R124 and need to do nothing.

For employees at companies running Ivanti software: no personal data breach has been reported. Watch for any IT communications asking you to reset passwords, a standard precaution your team might take even without confirmed exploitation. Ivanti says no other products are affected.

© 2026 Threat Vectr