IVANTI has released patches for four vulnerabilities in its Endpoint Manager (EPM) and Neurons for MDM products. The EPM update addresses three high-severity issues, including CVE-2026-18129, which involves cleartext transmission of sensitive information, and CVE-2026-18125, an out-of-bounds read flaw. Both flaws were fixed in EPM version 2024 SU7, along with a third high-severity input validation weakness (CVE-2026-18127). No exploitation of these vulnerabilities has been reported so far.
The Neurons for MDM platform received updates for a medium-severity command-injection vulnerability, fixed in version R124, that requires no customer action. Ivanti asserts that no other products are affected by these vulnerabilities.