Ivanti patches remotely exploitable flaws in Endpoint Manager
Ivanti released Endpoint Manager 2024 SU7 to fix three high‑severity flaws, including two remotely exploitable bugs that can leak SQL credentials via MitM or crash the EPM agent.
Enterprise software vendor Ivanti released Endpoint Manager update 2024 SU7 on Tuesday as part of its August 2026 security update, closing three high‑severity vulnerabilities. The company also deployed a separate fix to its Neurons for MDM cloud service earlier in June.
The SU7 update addresses CVE-2026-18129, CVE-2026-18125 and CVE-2026-18127. CVE-2026-18129 is a cleartext transmission issue that can expose credentials for external SQL connections if an attacker intercepts traffic. CVE-2026-18125 is an out‑of‑bounds read in the EPM agent that can be triggered to crash an agent service. CVE-2026-18127 is an input‑validation weakness that can be used to control filenames; an authenticated actor exploiting it could gain full write access to an S3 bucket configured for session recording storage.
Ivanti noted in its security bulletin that CVE-2026-18129 and CVE-2026-18125 can be exploited remotely without authentication, while the filename vulnerability requires an authenticated user.
Ivanti’s Neurons for MDM received a separate medium‑severity fix for a command‑injection vulnerability in release R124, deployed in late June. The Neurons patch has been applied to Ivanti’s cloud service and requires no customer action. The company said the Neurons issue did not meet the criteria for a CVE number and that there is no evidence it has been exploited in the wild.
Ivanti wrote: “We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure.” The company added that no other Ivanti products are affected and directed customers to its security bulletin for technical details and mitigation guidance.
Organizations using Endpoint Manager or Neurons for MDM should review Ivanti’s update notes and apply SU7 and R124 where applicable to protect SQL credentials and recorded session storage.








