Heise.De
Ivanti EPM Patches Critical Vulnerabilities Affecting Cloud and Database Security
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Ivanti has released updates for its Endpoint Manager (EPM) software to address three critical vulnerabilities. These vulnerabilities allow remote attackers to intercept sensitive database credentials, manipulate cloud storage configurations, and crash the agent service. The vulnerabilities are identified as CVE-2026-18129, CVE-2026-18127, and CVE-2026-18125, all published on August 11, 2026. The affected versions include EPM 2024 SU6 and earlier. Ivanti advises users to upgrade to version 2024 SU7 or newer to mitigate risks. Despite the severity, Ivanti reports no known exploitation of these vulnerabilities in the wild. IT managers are urged to act promptly to minimize potential threats. This follows a previous patch released in mid-May for other vulnerabilities in the same software.
Key Points: • Three critical vulnerabilities in Ivanti EPM allow remote attacks and data interception. • Affected versions include EPM 2024 SU6 and earlier; users must upgrade to SU7 or newer. • Ivanti reports no known exploitation of these vulnerabilities at customer sites.