Vulnerabilities & PatchesEmerging1 src
Ivanti Endpoint Manager Vulnerabilities Let Remote Attackers Crash Agent Service
Ivanti has issued a security advisory for Ivanti Endpoint Manager (EPM), disclosing three high-severity vulnerabilities that could allow remote attackers to crash agent services, hijack cloud storage configurations, and intercept sensitive database credentials.
Published on August 11, 2026, the advisory impacts all EPM 2024 SU6 and earlier deployments, urging security teams to update to the newly released 2024 SU7 build without delay.
Ivanti Endpoint Manager Vulnerabilities
The disclosed flaws span agent components, core management services, and external integrations: Tracked as CVE-2026-18125, this out-of-bounds read vulnerability in the EPM Agent carries a CVSS score of 7.5.
It enables a remote, unauthenticated attacker to crash the agent service on managed endpoints by sending crafted input, requiring no user interaction or valid credentials.