CVE Tools
Back to feed
Patch released Endpoint Manager Neurons for MDM Ivanti

Ivanti EPM Update Patches Remotely Exploitable Flaws

SecurityWeek·By Ionut Arghire··1 min read
CVE Tools coverage

Ivanti has released security updates addressing four vulnerabilities affecting its Endpoint Manager and Neurons for MDM products. The Endpoint Manager update resolves three high-severity issues, including CVE-2026-18129 and CVE-2026-18125, which allow remote unauthenticated attackers to perform man-in-the-middle credential theft or crash agent services via out-of-bounds reads. Additionally, the patch corrects CVE-2026-18127, an input validation flaw that could permit unauthorized file control in S3 buckets used for session recordings.

These fixes are available in Endpoint Manager version 2024 SU7, while the medium-severity command injection bug in Neurons for MDM was already addressed in version R124 without requiring customer action. Ivanti stated it is currently unaware of any active exploitation of these specific vulnerabilities.