Critical Ivanti Endpoint Manager CVEs Let Remote Attackers Crash Agent Service
Key Takeaways Ivanti has disclosed three high-severity vulnerabilities affecting its Endpoint Manager (EPM) product. These flaws could allow remote attackers to crash agent services, manipulate cloud...
Key Takeaways
- Ivanti has disclosed three high-severity vulnerabilities affecting its Endpoint Manager (EPM) product.
- These flaws could allow remote attackers to crash agent services, manipulate cloud storage, or intercept sensitive database credentials.
- All EPM versions up to and including 2024 SU6 are impacted.
- Patches are available in the newly released EPM 2024 SU7 build.
- While no active exploitation has been reported, immediate updates are strongly recommended.
Ivanti has issued a critical security advisory for its Endpoint Manager (EPM) solution, detailing three high-severity vulnerabilities. These flaws could enable remote attackers to disrupt agent services, hijack cloud storage configurations, and intercept sensitive database credentials, posing significant risks to enterprise environments.
Table Of Content
The advisory, published on August 11, 2026, impacts all EPM deployments running version 2024 SU6 and earlier. Organizations are urged to update to the recently released 2024 SU7 build without delay to mitigate these threats.
Ivanti Endpoint Manager Vulnerabilities Uncovered
The identified vulnerabilities span various components of Ivanti EPM, including agent components, core management services, and external integrations.
CVE-2026-18125: EPM Agent Out-of-Bounds Read
This vulnerability, tracked as CVE-2026-18125, is an out-of-bounds read flaw within the EPM Agent, carrying a CVSS score of 7.5. It allows an unauthenticated remote attacker to crash the agent service on managed endpoints by sending specially crafted input. The exploitation requires no user interaction or valid credentials.
While this issue does not facilitate code execution, its exploitation can severely disrupt endpoint management capabilities across an organization’s fleet, effectively blinding administrators during a critical outage. The flaw falls under CWE-125, a common memory-safety issue, emphasizing the importance of risk-based patching for robust endpoint security. Security researcher Hieu Tran Nam (jkana101) was credited with reporting this particular vulnerability.
CVE-2026-18127: External Control of Filename in EPM Core
Scoring 7.7 on the CVSS scale, CVE-2026-18127 stems from external control of a filename parameter (CWE-73) within the EPM Core component. This vulnerability enables an authenticated remote attacker to gain full write access over an Amazon S3 bucket that has been configured for session recording storage.
An attacker with even low-level privileges could exploit this to overwrite, modify, or plant malicious files within session recording archives. This could corrupt critical audit trails or establish a staging point for further attacks within the cloud infrastructure.
CVE-2026-18129: Cleartext Transmission of Sensitive Data
With the highest severity score of 8.1 (CVSS), CVE-2026-18129 involves the cleartext transmission of sensitive data within the EPM Core (CWE-295). An adversary positioned in a Man-in-the-Middle (MitM) network path can intercept unencrypted traffic, thereby leaking credentials used for external SQL database connections.
Given that exploitation requires no authentication or user interaction, this vulnerability presents a prime target for threat actors operating in unsegmented networks.
As detailed in the official Ivanti Security Advisory, these security flaws underscore the necessity for organizations managing both remote and on-premises endpoints to enforce strict network segmentation. Implementing automated patch management is also crucial to streamline security updates across distributed management infrastructure before threat actors develop active exploits.
All versions of Ivanti Endpoint Manager up to and including 2024 SU6 are affected by these vulnerabilities. Ivanti has addressed all three issues in EPM 2024 SU7, which is now available for download via the Ivanti License System (ILS). Organizations that rely on external SQL databases or S3-backed session logs should prioritize this patch cycle immediately.
Ivanti has stated that there is no evidence of active exploitation prior to their disclosure, and these bugs were identified through their responsible disclosure program. While there are currently no public Indicators of Compromise (IoCs), detection strategies should focus on monitoring endpoint telemetry for anomalous agent crashes, unauthorized S3 bucket writes, and unusual SQL authentication patterns. Considering Ivanti EPM’s history of recurring critical vulnerabilities, security teams are advised to expedite testing and deployment of this patch across their production environments.
What You Should Do
- Update Immediately: Upgrade all Ivanti Endpoint Manager deployments to version 2024 SU7 without delay. This is the most critical step to mitigate all three high-severity vulnerabilities.
- Implement Network Segmentation: Ensure strict network segmentation for your EPM infrastructure and managed endpoints to limit the impact of potential exploitation, especially for CVE-2026-18129.
- Monitor for Anomalous Activity: Continuously monitor endpoint telemetry for unexpected agent crashes (CVE-2026-18125), unauthorized writes to S3 buckets (CVE-2026-18127), and unusual SQL authentication patterns (CVE-2026-18129).
- Review Cloud Storage Configurations: Audit configurations for S3 buckets used with EPM, particularly those for session recording, to ensure least privilege access and detect any unauthorized modifications.
- Review SQL Database Connectivity: Verify that connections to external SQL databases are encrypted and not susceptible to cleartext credential interception.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.