Ivanti has announced Ivanti EPM updates for vulnerabilities in Endpoint Manager (EPM) and Neurons for MDM. For EPM, it concerns several high-severity bugs—two of which can be exploited remotely by remote, unauthenticated attackers. In addition, there is a fix for a medium-severity issue in Neurons for MDM.
In this article, we summarize the key points: which CVEs are involved, what the impact could be, and which versions Ivanti has addressed.
What Ivanti fixes in Endpoint Manager (EPM)
For Endpoint Manager, Ivanti publishes patches for a total of three high-severity vulnerabilities. Two are described in the advisory as remote exploitable by remote, unauthenticated attackers. In other words: an attacker does not need to be logged in to attempt exploitation.
CVE-2026-18129: sensitive data exposure via MitM
The first vulnerability, CVE-2026-18129, concerns cleartext transmission of sensitive information. If an attacker can position themselves between communications—for example in a man-in-the-middle (MitM) scenario—they could potentially intercept data. Ivanti states this can lead to credential leakage for external SQL connections.
This type of flaw is especially relevant for environments where EPM creates or manages network traffic that is sensitive. If protection against interception is insufficient, the risk increases that authentication data or other information could become available to an attacker.
CVE-2026-18125: out-of-bounds read in the EPM agent
The second high-severity bug is CVE-2026-18125. It is described as an out-of-bounds read in the EPM agent. By triggering the issue, an attacker can cause a crash of an agent service.
While a crash does not automatically mean an attacker gains direct access to systems, it can disrupt operational continuity of management agents. Additionally, a crash can sometimes contribute to further investigation or exploitation, depending on how the environment is configured.
CVE-2026-18127: input validation and file names
In addition to the two issues above, Ivanti also addresses CVE-2026-18127. This is also high-severity and involves an input validation weakness that could allow remote attackers to exert filename control.
Ivanti reports a specific scenario: an authenticated threat actor could use this to gain full write control over an S3 bucket that is configured for session recording storage.
For organizations that use session recording, this is an important point. Write control over storage can affect the integrity of recorded sessions and the way data is later managed or accessed.
Which EPM version fixes the problems?
Ivanti states that the two security defects (CVE-2026-18129 and CVE-2026-18125) are fixed in EPM 2024 SU7. The same version also patches the third vulnerability, CVE-2026-18127.
If your organization is not running EPM 2024 SU7 operationally, Ivanti says this is the right moment to prioritize patching. Especially because there are remote exploitation possibilities and a MitM-like data exposure scenario.
Want more context on patch prioritization for remote vulnerabilities? Read also: Cisco firewall zero-day patched: DoS via HTTP.
Neurons for MDM: fix for command injection
Alongside Endpoint Manager, Ivanti has also updated Neurons for MDM. Here, it is one medium-severity vulnerability: a command-injection issue that can be exploited remotely to enable disclosure of sensitive information.
According to Ivanti, the vulnerability is patched in Neurons for MDM version R124 of the cloud-based SaaS platform. The fix was implemented in late June.
No customer action required
Ivanti indicates that the solution requires no customer action. Since this is a cloud SaaS component, the repair is included as part of the platform delivery. Ivanti also reports that the vulnerability did not meet the criteria to reserve a CVE number and that there are no indications of exploitation in the wild.
If you look at MDM and enterprise management risks more broadly, it can help to consistently factor incidents involving management components into your security process.
Have these vulnerabilities been exploited already?
Ivanti says that at the time of public disclosure, there were no customers known to have exploited the EPM vulnerabilities. That is a positive sign, but it’s still wise not to delay the update, because remote exploitation scenarios (such as MitM-like data exposure and out-of-bounds behavior) can be taken up quickly once proof-of-concept code or tooling circulates.
The same applies to the Neurons for MDM issue: according to Ivanti, there is no evidence that the problem is already being used in attacks.
Overlaps: which products are affected?
Ivanti emphasizes that no other products are impacted by these specific vulnerabilities. This generally makes the patch guidance clearer: focus on the mentioned EPM and Neurons components within your Ivanti environment.
For organizations that need to process multiple vendor updates at the same time, it helps to map security updates to your existing asset inventory. Therefore, include EPM and Neurons for MDM explicitly in your upgrade planning.
Why these updates deserve extra attention
The Ivanti EPM updates have a few characteristics that make them especially relevant for many enterprise environments:
- Remote, unauthenticated exploitability for two EPM issues, lowering the bar for attackers.
- A MitM-related exposure scenario that can lead to credential leakage for external SQL connections.
- An input validation problem that, in an authenticated scenario, can result in write control over session recording storage in S3.
- For Neurons for MDM: a cloud-patched fix, without customers needing to upgrade themselves.
Together, this means patching is not only about “technical hygiene”, but also direct risk management for management and storage flows.
Practical approach for your patch planning
To reduce the chance of problems caused by delayed deployment, you can structure patching:
- Inventory which EPM version you run and whether 2024 SU7 has been implemented.
- Link session recording and S3 settings to the used EPM/agent components, so you know where write control impact may occur.
- Check whether Neurons for MDM in your organization has been updated to R124 (and document that no customer action was required).
- Monitor after the update for agent stability (for CVE-2026-18125) and for network or data flows toward external SQL endpoints.
If your patch policy is tied to release windows, also leave room for security urgency. Not every vulnerability requires the same speed, but remotely exploitable bugs typically do.
More examples of how rapid patching in enterprise platforms plays out in concrete improvements can be found in related coverage, such as August 2026 Patch Tuesday: focus on Microsoft fixes.
Conclusion
With Ivanti EPM updates, Ivanti has patched multiple vulnerabilities in Endpoint Manager and Neurons for MDM. In EPM, it involves three high-severity CVEs, including two issues that can be exploited remotely and without authentication. The fixes are included in EPM 2024 SU7. For Neurons for MDM, the command-injection bug has been patched in R124, and according to Ivanti it requires no customer action.
The message is clear: upgrade EPM to the specified versions and make sure your environment is not lagging behind—especially because remote exploitation scenarios and potential data exposures are in scope.
Source: https://www.securityweek.com/ivanti-epm-update-patches-remotely-exploitable-flaws/
