Ivanti has released a critical security advisory regarding its Endpoint Manager (EPM) software, revealing three significant vulnerabilities that could allow remote attackers to disrupt services, manipulate cloud storage settings, and access sensitive database information.
Issued on August 11, 2026, the advisory affects all versions up to EPM 2024 SU6. Users are strongly advised to upgrade to the newly available 2024 SU7 version to mitigate these risks.
Understanding the Ivanti Endpoint Manager Flaws
The vulnerabilities impact various components of the Endpoint Manager, including agent services, core management functionalities, and external system integrations. The first, identified as CVE-2026-18125, is an out-of-bounds read flaw with a CVSS score of 7.5. This defect permits attackers to crash agent services remotely without needing user credentials.
Although it doesn’t enable code execution, this vulnerability can significantly impair endpoint management across an organization, leaving systems vulnerable to outages. It highlights the necessity of risk-based patching strategies to maintain robust endpoint security.
Critical Vulnerability Ratings and Implications
The second issue, CVE-2026-18127, involves manipulating a filename parameter within the EPM Core, scoring 7.7 on the CVSS scale. This vulnerability allows attackers with valid credentials to gain control over Amazon S3 storage setups used for session recordings. Malicious actors could modify or insert files into session archives, potentially undermining audit logs or setting up a breach point in the cloud infrastructure.
The most severe vulnerability, CVE-2026-18129, carries a CVSS score of 8.1. It involves the transmission of unencrypted data, which could be intercepted by attackers using a Man-in-the-Middle (MitM) technique. This flaw makes it possible to capture credentials for external SQL databases, posing a significant risk to network security, especially in unsegmented environments.
Mitigation and Future Considerations
According to the Ivanti Security Advisory, these vulnerabilities emphasize the importance of stringent network segmentation for organizations managing remote and on-premises endpoints. Automated patch management is recommended to facilitate timely security updates across distributed systems before potential exploits are developed by threat actors.
All versions up to EPM 2024 SU6 are susceptible to these vulnerabilities, but Ivanti has addressed them in the EPM 2024 SU7 release, now available for download. Organizations particularly reliant on external SQL databases or S3-based session logs should prioritize this patch.
Ivanti reports no known active exploitations prior to the advisory, attributed to its responsible disclosure program. Hieu Tran Nam (jkana101) is credited with identifying CVE-2026-18125.
Currently, there are no public indicators of compromise, but detection can be achieved by monitoring for unusual agent crashes, unauthorized S3 writes, and abnormal SQL authentication activities. Given the history of critical vulnerabilities associated with Ivanti EPM, security teams are urged to expedite the update process across their production environments.
