Ivanti Endpoint Manager Vulnerabilities Let Remote Attackers Crash Agent Service

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Ivanti Endpoint Manager Vulnerabilities Let Remote Attackers Crash Agent Service, Hijack Storage, and Leak Credentials
Ivanti has issued a security advisory for Ivanti Endpoint Manager (EPM), disclosing three high-severity vulnerabilities that could allow remote attackers to crash agent services, hijack cloud storage configurations, and intercept sensitive database credentials.

Published on August 11, 2026, the advisory impacts all EPM 2024 SU6 and earlier deployments, urging security teams to update to the newly released 2024 SU7 build without delay.

Ivanti Endpoint Manager Vulnerabilities

The disclosed flaws span agent components, core management services, and external integrations: Tracked as CVE-2026-18125, this out-of-bounds read vulnerability in the EPM Agent carries a CVSS score of 7.5.

It enables a remote, unauthenticated attacker to crash the agent service on managed endpoints by sending crafted input, requiring no user interaction or valid credentials.

While it does not allow code execution, exploiting this bug disrupts endpoint management capabilities across an enterprise fleet, blinding administrators during an outage.

The flaw falls under CWE-125, a classic memory-safety issue that underscores why adopting risk-based patching is vital for endpoint security.

Scoring 7.7 (CVSS), CVE-2026-18127 arises from external control of a filename parameter in the EPM Core component (CWE-73). This enables an authenticated remote attacker to gain full write access over an Amazon S3 bucket configured for session recording storage.

An attacker with low-level privileges could overwrite, modify, or plant files inside session recording archives, corrupting audit trails or establishing a staging point in cloud infrastructure.

Carrying the highest severity score of 8.1 (CVSS), CVE-2026-18129 involves cleartext transmission of sensitive data in the EPM Core (CWE-295).

An adversary positioned in a Man-in-the-Middle (MitM) network path can intercept unencrypted traffic to leak credentials used for external SQL database connections.

Because exploitation requires no authentication or user interaction, it represents a prime target for threat actors targeting unsegmented networks.

As detailed in the official Ivanti Security Advisory, these security flaws highlight why organizations managing remote and on-premises endpoints must enforce strict network segmentation.

Implementing automated patch management helps streamline security updates across distributed management infrastructure before threat actors develop active exploits.

CVE ID Vulnerability Type & CWE CVSS Score Impact / Exploitation Path
CVE-2026-18125 Out-of-Bounds Read (CWE-125) 7.5 Unauthenticated remote crash of EPM Agent service
CVE-2026-18127 External Control of Filename (CWE-73) 7.7 Authenticated write control over S3 session recording buckets
CVE-2026-18129 Cleartext Information Transmission (CWE-295) 8.1 MitM interception of cleartext SQL database credentials

All versions of Ivanti Endpoint Manager up to and including 2024 SU6 are affected. Ivanti has fixed all three vulnerabilities in EPM 2024 SU7, which is currently available for download through the Ivanti License System (ILS). Organizations relying on external SQL databases or S3-backed session logs should prioritize this patch cycle immediately.

According to Ivanti, there is no evidence of active exploitation prior to disclosure, and the bugs were identified through its responsible disclosure program. Security researcher Hieu Tran Nam (jkana101) was credited with reporting CVE-2026-18125.

Because there are currently no public indicators of compromise (IoCs), detection relies on monitoring endpoint telemetry for anomalous agent crashes, unauthorized S3 bucket writes, and unusual SQL authentication patterns.

Given Ivanti EPM’s history of recurring critical vulnerabilities, security teams should expedite testing and deployment across production environments.

[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now