Ivanti has disclosed three high-severity vulnerabilities in its Endpoint Manager (EPM) software, potentially allowing remote attackers to disrupt services, manipulate cloud storage configurations, and access sensitive database credentials. These vulnerabilities affect all EPM 2024 SU6 and earlier versions, prompting an urgent recommendation for organizations to upgrade to the newly released 2024 SU7.
Details of the Vulnerabilities
The identified vulnerabilities are as follows:
- CVE-2026-18125: An out-of-bounds read flaw in the EPM Agent, with a CVSS score of 7.5. This vulnerability enables unauthenticated remote attackers to crash the agent service on managed endpoints by sending specially crafted inputs, leading to potential disruptions in endpoint management across an organization.
- CVE-2026-18127: An external control of filename parameter issue in the EPM Core component, carrying a CVSS score of 7.7. Authenticated remote attackers can exploit this to gain write access over an Amazon S3 bucket used for session recording storage, allowing them to overwrite or insert files, thereby compromising audit trails or establishing a foothold within cloud infrastructure.
- CVE-2026-18129: A cleartext transmission of sensitive data vulnerability in the EPM Core, with a CVSS score of 8.1. Attackers positioned in a Man-in-the-Middle (MitM) scenario can intercept unencrypted traffic to obtain credentials for external SQL database connections, posing significant risks to data confidentiality.
Implications and Recommendations
These vulnerabilities underscore the critical need for organizations to implement robust network segmentation and automated patch management strategies. While there is currently no evidence of active exploitation, the potential impact of these flaws necessitates immediate action. Ivanti has addressed these issues in EPM 2024 SU7, now available for download through the Ivanti License System (ILS). Organizations utilizing external SQL databases or S3-backed session logs should prioritize this update to mitigate potential risks.
Given the recurring nature of critical vulnerabilities in Ivanti’s EPM, security teams are advised to expedite testing and deployment of the latest updates across production environments to maintain system integrity and security.