CVE Tools

Ivanti EPM Update Patches Remotely Exploitable Flaws

SecurityWeekBy Ionut Arghire

PatchEndpoint ManagerNeurons for MDM

Our summary

Ivanti has released security updates addressing four vulnerabilities affecting its Endpoint Manager and Neurons for MDM products. The Endpoint Manager update resolves three high-severity issues, including CVE-2026-18129 and CVE-2026-18125, which allow remote unauthenticated attackers to perform man-in-the-middle credential theft or crash agent services via out-of-bounds reads. Additionally, the patch corrects CVE-2026-18127, an input validation flaw that could permit unauthorized file control in S3 buckets used for session recordings.

These fixes are available in Endpoint Manager version 2024 SU7, while the medium-severity command injection bug in Neurons for MDM was already addressed in version R124 without requiring customer action. Ivanti stated it is currently unaware of any active exploitation of these specific vulnerabilities.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store