Ivanti patches remotely exploitable Endpoint Manager flaws including credential leak issue CVE-2026-18129

Ivanti has released security fixes for multiple vulnerabilities in Endpoint Manager that could let attackers steal credentials, crash services, or abuse storage settings. The EPM update fixes CVE-2026-18129, a man-in-the-middle flaw exposing external SQL connection credentials, CVE-2026-18125, an out-of-bounds read that can crash the EPM agent service, and CVE-2026-18127, which can let an authenticated attacker control filenames and gain full write access to an S3 bucket used for session recording. The fixes are in EPM 2024 SU7. Ivanti also said a separate remotely exploitable command-injection flaw in the cloud-based Neurons for MDM service was patched in R124 in late June.
Why it matters: Organizations using Ivanti Endpoint Manager should treat this as a practical patching issue because two of the EPM bugs can be reached remotely and one can expose credentials. Update EPM to 2024 SU7 promptly and review whether EPM uses external SQL connections or S3-backed session recording storage.

Sources

Ivanti EPM Update Patches Remotely Exploitable Flaws
Ionut Arghire 2026.08.12 100% relevant
This article appears to be the first tracked item establishing the August 2026 Ivanti EPM and Neurons for MDM vulnerability and patch event.
← Back to all stories