Ivanti EPM Update Patches Remotely Exploitable Flaws

Ivanti EPM Update Patches Remotely Exploitable Flaws
Ivanti has released patches for four vulnerabilities affecting Endpoint Manager (EPM) and Neurons for MDM, including issues that could let remote attackers leak credentials, crash services, or control filenames. The company says it has seen no evidence of exploitation in the wild and that no other Ivanti products are impacted. #Ivanti #EndpointManager #NeuronsforMDM #CVE-2026-18129 #CVE-2026-18125 #CVE-2026-18127

Keypoints

  • Ivanti patched four vulnerabilities in Endpoint Manager and Neurons for MDM.
  • CVE-2026-18129 could expose credentials for external SQL connections through cleartext transmission.
  • CVE-2026-18125 is an out-of-bounds read flaw that can crash an EPM agent service.
  • CVE-2026-18127 may let remote attackers control filenames and affect S3 session recording storage.
  • Ivanti says no customers were known to be exploited and no other products are affected.

Read More: https://www.securityweek.com/ivanti-epm-update-patches-remotely-exploitable-flaws/