VYPR
patchPublished Aug 11, 2026· 1 source

Ivanti Endpoint Manager Hit by Three High-Severity Vulnerabilities

Ivanti has released security advisories for Endpoint Manager (EPM) versions 2024 SU6 and earlier, addressing three high-severity vulnerabilities that could allow remote attackers to crash agent services, hijack cloud storage configurations, and intercept SQL database credentials.

Ivanti has issued a security advisory for its Endpoint Manager (EPM) product, detailing three high-severity vulnerabilities that could enable remote attackers to disrupt agent services, compromise cloud storage configurations, and steal sensitive database credentials. The advisory, released on August 11, 2026, affects all deployments of EPM 2024 SU6 and earlier versions, with Ivanti urging immediate upgrades to the newly released 2024 SU7 build.

The first vulnerability, tracked as CVE-2026-18125, is an out-of-bounds read flaw within the EPM Agent, carrying a CVSS score of 7.5. This vulnerability allows an unauthenticated remote attacker to crash the agent service on managed endpoints by sending specially crafted input. While it does not permit code execution, the successful exploitation of this flaw can lead to a significant disruption of endpoint management capabilities across an entire enterprise, effectively blinding administrators.

CVE-2026-18127, rated at CVSS 7.7, stems from an issue related to the external control of a filename parameter within the EPM Core component. This vulnerability enables an authenticated remote attacker to gain complete write access to an Amazon S3 bucket that is configured for storing session recordings. An attacker with even low-level privileges could potentially overwrite, modify, or inject files into session recording archives, thereby corrupting audit trails or establishing a foothold within the organization's cloud infrastructure.

The third vulnerability, CVE-2026-18129, holds the highest severity score of 8.1 (CVSS) and involves the cleartext transmission of sensitive data within the EPM Core. Adversaries positioned in a Man-in-the-Middle (MitM) network path could intercept unencrypted traffic to exfiltrate credentials used for connecting to external SQL databases. The lack of authentication or user interaction requirements for exploitation makes this a prime target for threat actors operating on unsegmented networks.

All versions of Ivanti Endpoint Manager up to and including 2024 SU6 are impacted by these vulnerabilities. Ivanti has provided fixes for all three issues in EPM 2024 SU7, which is now available for download via the Ivanti License System (ILS). Organizations that rely on external SQL databases or S3-backed session logs are strongly advised to prioritize this patch cycle.

According to Ivanti, there is currently no evidence of active exploitation of these vulnerabilities prior to their disclosure. The flaws were identified through Ivanti's responsible disclosure program, with security researcher Hieu Tran Nam (jkana101) credited for reporting CVE-2026-18125. In the absence of public indicators of compromise (IoCs), detection strategies should focus on monitoring endpoint telemetry for unusual agent crashes, unauthorized S3 bucket modifications, and anomalous SQL authentication patterns.

Given Ivanti EPM's history of recurring critical vulnerabilities, security teams should expedite the testing and deployment of the latest patch across their production environments to mitigate potential risks.

Synthesized by Vypr AI