Ivanti releases critical patches for Endpoint Manager vulnerabilities targeting credentials and S3 buckets
Ivanti has released critical updates to address multiple high-severity vulnerabilities in Endpoint Manager (EPM) that could lead to credential theft and unauthorized S3 bucket control. Defenders using EPM should prioritize updating to version 2024 SU7 immediately. There is currently no evidence of these flaws being exploited in the wild.
Summary
Ivanti announced patches for several security defects affecting its Endpoint Manager (EPM) and Neurons for MDM products. The update addresses three high-severity vulnerabilities within EPM, two of which can be triggered by remote, unauthenticated attackers.
While Ivanti stated they are not aware of any customers being exploited by these specific vulnerabilities at the time of disclosure, the flaws present significant risks to credential security and service availability. Additionally, a medium-severity command-injection flaw was addressed in the Neurons for MDM cloud-based SaaS platform via version R124.
Technical details
The EPM update targets three distinct high-severity issues:
- CVE-2026-18129: This vulnerability involves the cleartext transmission of sensitive information. An attacker positioned in a man-in-the-middle (MitM) position can exploit this to leak credentials used for external SQL connections.
- CVE-2026-18125: An out-of-bounds read flaw exists within the EPM agent. This defect can be triggered to crash an agent service, resulting in a denial of service.
- CVE-2026-18127: This input validation weakness allows remote attackers to control filenames. If an authenticated threat actor exploits this, they could gain full write control over an S3 bucket configured for session recording storage.
The Neurons for MDM vulnerability is a medium-severity command-injection flaw that could allow remote attackers to disclose sensitive information. This issue did not meet the criteria for a CVE reservation and was patched in version R124 in late June.
Affected products and fixed versions
| Product | Vulnerability | Severity | Fixed Version |
|---|---|---|---|
| Ivanti Endpoint Manager (EPM) | CVE-2026-18129 | High | 2024 SU7 |
| Ivanti Endpoint Manager (EPM) | CVE-2026-18125 | High | 2024 SU7 |
| Ivanti Endpoint Manager (EPM) | CVE-2026-18127 | High | 2024 SU7 |
| Ivanti Neurons for MDM | Command Injection | Medium | R124 |
Defender guidance
For organizations running Ivanti Endpoint Manager, the primary defense is upgrading to version 2024 SU7.
Because CVE-2026-18129 involves cleartext transmission of SQL credentials during a man-in-the-middle attack, network administrators should ensure that all external SQL connections are protected by encrypted channels to prevent credential leakage.
For those using the Neurons for MDM cloud-based SaaS platform, no manual action is required as the flaw was addressed in version R124 released in late June. However, verifying your current platform version can confirm the fix is active.
