Ivanti Patches Three High-Severity Flaws in Endpoint Manager That Attackers Could Hit Remotely
Two of the bugs needed no password to exploit. Ivanti says no customers were hit before the fixes landed.

Key points
- Ivanti patched three high-severity vulnerabilities in Endpoint Manager (EPM) on Tuesday, August 2026, fixing all three in version 2024 SU7.
- Two of the three flaws could be exploited by a remote attacker with no login credentials required.
- A fourth, medium-severity flaw in Ivanti Neurons for MDM was quietly fixed in June 2026 in version R124 and requires no action from customers.
- Ivanti says it has no evidence any of the four vulnerabilities were exploited before patches were released.
Ivanti, a company that makes software businesses use to manage and secure large fleets of computers and mobile devices, released security fixes Tuesday for four vulnerabilities across two of its products. Three of those flaws are rated high severity.
All three high-severity bugs sit inside Ivanti Endpoint Manager (EPM), which is the software IT teams use to control and monitor the devices on a corporate network. The fixes are bundled into EPM version 2024 SU7.
How bad are these flaws?
Two of the three bugs are serious enough that an outside attacker needs no username or password to start exploiting them. That is the detail defenders should focus on.
The first, CVE-2026-18129, is a "cleartext transmission" flaw, meaning the software was sending sensitive login credentials across a network in plain, readable text rather than encrypting them. An attacker positioned between two systems on the same network, a technique called a "man-in-the-middle" attack, could silently read those credentials as they passed by.
The second unauthenticated flaw, CVE-2026-18125, is an "out-of-bounds read" bug inside the EPM software agent, a small background program that runs on managed devices. Triggering it crashes that agent service, effectively knocking out the management software on a device.
The third high-severity bug, CVE-2026-18127, does require a valid login. Once inside, an attacker could manipulate filenames in a way that gives them full write access to an S3 bucket, which is a cloud storage container, configured to record user sessions. That is a meaningful post-login escalation.
| CVE ID | Severity | Needs Login? | What it does |
|---|---|---|---|
| CVE-2026-18129 | High | No | Leaks database credentials over the network |
| CVE-2026-18125 | High | No | Crashes the EPM agent service |
| CVE-2026-18127 | High | Yes | Grants full write access to cloud session-recording storage |
| (no CVE assigned) | Medium | No | Command injection in Neurons for MDM, fixed in R124 |
Should IT teams act urgently?
Yes, specifically on the two no-login-required flaws. Ivanti told customers it has no evidence of exploitation before disclosure, which is the good news. The patch exists now, so the window narrows the longer organisations wait.
Administrators running EPM should update to version 2024 SU7 as soon as their change-management process allows. Customers using Ivanti Neurons for MDM, a cloud-based mobile device management service, received the fix automatically in late June in version R124 and need to do nothing.
For ordinary employees at companies that use Ivanti software: no personal data breach has been reported, and Ivanti says no customers were actively exploited. Watch for any unusual IT communications asking you to reset passwords, as that would be a standard precaution your IT team might take even without confirmed exploitation. As first reported by SecurityWeek, Ivanti says no other products are affected.



