Ivanti, a prominent player in enterprise software solutions, has released important patches for vulnerabilities located in its Endpoint Manager (EPM) and Neurons for MDM platforms. These updates, announced on Tuesday, address four significant security flaws, thereby enhancing the safety and reliability of these systems.
Details of EPM Vulnerabilities
The latest EPM update mitigates three high-severity vulnerabilities that were previously susceptible to exploitation by remote, unauthenticated attackers. Among these, the flaw identified as CVE-2026-18129 involves the transmission of sensitive information in cleartext, which could potentially be intercepted by attackers in a man-in-the-middle (MitM) position to access credentials for external SQL connections.
Another vulnerability, CVE-2026-18125, is characterized by an out-of-bounds read error within the EPM agent. This defect could be exploited to crash an agent service, highlighting the critical nature of these patches. Furthermore, the update resolves CVE-2026-18127, an input validation weakness that could enable remote attackers to manipulate filenames if left unaddressed.
Resolution and Impact
The vulnerabilities have been successfully addressed in EPM version 2024 SU7. In addition, an authenticated attacker could exploit the input validation flaw to attain full write control over an S3 bucket configured for session recording storage. Despite the potential risks, Ivanti has indicated that, at the time of disclosure, no customers have reported exploitation of these vulnerabilities.
Updates to Neurons for MDM
In a related update, Ivanti Neurons for MDM received a fix for a medium-severity command-injection vulnerability. This flaw, which could be remotely exploited to reveal sensitive information, was corrected in version R124 of the cloud-based software as a service (SaaS) platform in late June. Ivanti assures users that no customer intervention is required for this patch, and the vulnerability did not meet the criteria for a CVE number allocation. Importantly, there is no evidence of this flaw being actively exploited.
Ivanti affirms that no other products within its ecosystem are impacted by these vulnerabilities. For additional details, users are encouraged to review Ivanti’s August 2026 security update announcement.
The timely release of these patches underscores Ivanti’s commitment to maintaining robust security measures across its product suite, providing users with enhanced protection against potential cybersecurity threats.
