← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 11, 2026 · 15:06via Cyber Security News

Ivanti Endpoint Manager Vulnerabilities Let Remote Attackers Crash Agent Service

Brief

Ivanti has issued a security advisory for Ivanti Endpoint Manager (EPM), disclosing three high-severity vulnerabilities that could allow remote attackers to crash agent services, hijack cloud storage configurations, and intercept sensitive database credentials.

Published on August 11, 2026, the advisory impacts all EPM 2024 SU6 and earlier deployments, urging security teams to update to the newly released 2024 SU7 build without delay.

Ivanti Endpoint Manager Vulnerabilities

The disclosed flaws span agent components, core management services, and external integrations: Tracked as CVE-2026-18125, this out-of-bounds read vulnerability in the EPM Agent carries a CVSS score of 7.5.

It enables a remote, unauthenticated attacker to crash the agent service on managed endpoints by sending crafted input, requiring no user interaction or valid credentials.

Read more on Cyber Security News