All stories

Ivanti releases critical patches for Endpoint Manager vulnerabilities targeting credentials and S3 buckets

Ivanti has released critical updates to address multiple high-severity vulnerabilities in Endpoint Manager (EPM) that could lead to credential theft and unauthorized S3 bucket control. Defenders using EPM should prioritize updating to version 2024 SU7 immediately. There is currently no evidence of these flaws being exploited in the wild.

Summary

Ivanti announced patches for several security defects affecting its Endpoint Manager (EPM) and Neurons for MDM products. The update addresses three high-severity vulnerabilities within EPM, two of which can be triggered by remote, unauthenticated attackers.

While Ivanti stated they are not aware of any customers being exploited by these specific vulnerabilities at the time of disclosure, the flaws present significant risks to credential security and service availability. Additionally, a medium-severity command-injection flaw was addressed in the Neurons for MDM cloud-based SaaS platform via version R124.

Technical details

The EPM update targets three distinct high-severity issues:

  • CVE-2026-18129: This vulnerability involves the cleartext transmission of sensitive information. An attacker positioned in a man-in-the-middle (MitM) position can exploit this to leak credentials used for external SQL connections.
  • CVE-2026-18125: An out-of-bounds read flaw exists within the EPM agent. This defect can be triggered to crash an agent service, resulting in a denial of service.
  • CVE-2026-18127: This input validation weakness allows remote attackers to control filenames. If an authenticated threat actor exploits this, they could gain full write control over an S3 bucket configured for session recording storage.

The Neurons for MDM vulnerability is a medium-severity command-injection flaw that could allow remote attackers to disclose sensitive information. This issue did not meet the criteria for a CVE reservation and was patched in version R124 in late June.

Affected products and fixed versions

Product Vulnerability Severity Fixed Version
Ivanti Endpoint Manager (EPM) CVE-2026-18129 High 2024 SU7
Ivanti Endpoint Manager (EPM) CVE-2026-18125 High 2024 SU7
Ivanti Endpoint Manager (EPM) CVE-2026-18127 High 2024 SU7
Ivanti Neurons for MDM Command Injection Medium R124

Defender guidance

For organizations running Ivanti Endpoint Manager, the primary defense is upgrading to version 2024 SU7.

Because CVE-2026-18129 involves cleartext transmission of SQL credentials during a man-in-the-middle attack, network administrators should ensure that all external SQL connections are protected by encrypted channels to prevent credential leakage.

For those using the Neurons for MDM cloud-based SaaS platform, no manual action is required as the flaw was addressed in version R124 released in late June. However, verifying your current platform version can confirm the fix is active.

Sources

  1. https://www.securityweek.com/ivanti-epm-update-patches-remotely-exploitable-flaws/
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -