Ivanti has addressed several high-severity security issues across its administrative management stack, releasing critical software updates to resolve an Ivanti Endpoint Manager vulnerability set that could allow remote attackers to sniff external database credentials, force endpoint agent crashes, or compromise cloud storage buckets.
The August 2026 updates resolve three high-severity flaws in Ivanti Endpoint Manager (EPM) alongside a medium-severity command-injection vulnerability in the cloud-native Ivanti Neurons for MDM platform. While Ivanti reports no evidence of active zero-day exploitation prior to disclosure, management utilities like EPM are high-value targets for enterprise network intrusions due to their centralized access, administrative privileges, and high-trust placement within internal networks.
Technical Breakdown of the Vulnerabilities
The most impactful updates focus on the on-premises EPM architecture, addressing defects that span network traffic security, memory safety, and cloud integration boundaries:
- CVE-2026-18129 (High Severity): Cleartext Transmission of Sensitive Information. An unauthenticated attacker positioned in a man-in-the-middle (MitM) network path can intercept management communications and extract cleartext credentials for external SQL connections. Because EPM relies on central SQL databases to maintain inventory, policy configurations, and system telemetry, obtaining these database credentials can allow an adversary to access, manipulate, or pivot into underlying database servers.
- CVE-2026-18125 (High Severity): Out-of-Bounds Read in EPM Agent. This vulnerability stems from improper boundary checking when the endpoint agent parses incoming network traffic. An unauthenticated remote attacker can issue malformed requests to crash the endpoint agent service. Disabling agent operations blinds system administrators to host activity and disrupts local enforcement policies, creating blind spots during an intrusion.
- CVE-2026-18127 (High Severity): Improper Input Validation. This vulnerability allows remote, authenticated threat actors to gain arbitrary control over generated filenames. In configurations where EPM streams session recordings to an Amazon Web Services (AWS) S3 bucket, an attacker can exploit this weakness to obtain full write control over the designated storage bucket, potentially overwriting audit trails, uploading malicious artifacts, or altering archived session logs.
Separately, Ivanti patched a medium-severity command-injection vulnerability in Neurons for MDM. This issue allowed remote attackers to disclose sensitive platform information. Because Neurons for MDM operates as a SaaS platform, Ivanti resolved the defect directly in version R124 during late June 2026. Ivanti determined the flaw did not meet the standard vulnerability assignment criteria to reserve a CVE identifier.
Operational Blast Radius and Enterprise Risk
Endpoint management platforms like Ivanti EPM represent a critical trust boundary in enterprise security architectures. Agents running on user endpoints operate with elevated system-level permissions (SYSTEM on Windows or root on Unix-like environments) to perform software distribution, patch enforcement, and remote administration tasks.
When vulnerabilities manifest in platforms of this nature, the blast radius extends far beyond a single affected workload:
- Credential Exposure: In unsegmented or partially compromised enterprise networks, network eavesdropping via CVE-2026-18129 provides lateral-movement primitives. Sniffing SQL connection strings grants direct access to backend data stores, which frequently house service account details, domain trust configurations, and management scripts.
- Telemetry Blinding: Blasting EPM agents offline using CVE-2026-18125 gives attackers a mechanism to suppress enterprise monitoring. By systematically crashing agents across critical subnets, threat actors can hide secondary execution payloads or delay defensive response teams.
- Audit and Compliance Tampering: Storage bucket write access via CVE-2026-18127 compromises forensic integrity. Attackers who gain access to session recording storage can manipulate historical remote control logs, preventing security operation centers (SOC) from verifying what actions were taken during administrative sessions.
Remediation Strategy
Ivanti has released standalone updates and cloud-side hotfixes to address these flaws. Administrators should prioritize upgrading management core servers and deploying updated agents to endpoints immediately.
- Ivanti Endpoint Manager (EPM): Apply EPM version 2024 SU7 to core management servers and push the updated agent binaries out to all managed endpoints to remediate CVE-2026-18129, CVE-2026-18125, and CVE-2026-18127.
- Ivanti Neurons for MDM: No administrator action is required. Ivanti automatically updated the SaaS platform to version R124 in late June 2026.
- Network & Storage Hardening: Ensure EPM server-to-agent network traffic paths enforce strict TLS validation to neutralize MitM vectors prior to patch application, and review identity and access management (IAM) permissions on connected AWS S3 recording buckets to limit exposure to unexpected file write operations.
Related content
Cisco Warns of High-Severity ClamAV ZIP Parsing Flaws with Public Exploit Code
Security NewsGoogle Password Manager Passkey Flaws Allow Silent Account Hijacking
Security NewsCISA Mandates Immediate Patch for Actively Exploited Progress LoadMaster RCE Flaw
Security NewsUK ACRO Criminal Records Office Reprimanded After Unpatched CMS Led to Two-Year Breach
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call