www.securityweek.com 8/12/2026, 8:31:58 AM · external

Ivanti patches critical EPM flaws, including cleartext data leak

Ivanti patches critical EPM flaws, including cleartext data leak
CyberSIXT Evidence Panel

IVANTI has released patches for four vulnerabilities in its Endpoint Manager (EPM) and Neurons for MDM products. The EPM update addresses three high-severity issues, including CVE-2026-18129, which involves cleartext transmission of sensitive information, and CVE-2026-18125, an out-of-bounds read flaw. Both flaws were fixed in EPM version 2024 SU7, along with a third high-severity input validation weakness (CVE-2026-18127). No exploitation of these vulnerabilities has been reported so far.

The Neurons for MDM platform received updates for a medium-severity command-injection vulnerability, fixed in version R124, that requires no customer action. Ivanti asserts that no other products are affected by these vulnerabilities.

View Primary Source Via www.securityweek.com

Article by CyberSIXT