VORANT. Threat Intelligence Sign in Get the full feed

Ivanti patches EPM and Neurons MDM flaws

routine vulnerability technology

CERT-FR advisory details multiple vulnerabilities in Ivanti Endpoint Manager and Neurons for MDM allowing DoS, data integrity and confidentiality breaches.

CERT-FR published an advisory covering multiple vulnerabilities in Ivanti Endpoint Manager (EPM) versions prior to 2024 SU7 and Ivanti Neurons for MDM versions prior to R124. The flaws, tracked as CVE-2026-18125, CVE-2026-18127, and CVE-2026-18129, could allow an attacker to cause a remote denial of service, compromise data confidentiality, or affect data integrity, with some also enabling a bypass of security policy.

Ivanti released corresponding security bulletins on August 11, 2026, and administrators are advised to apply the vendor-provided patches referenced in the advisory. No evidence of active exploitation is mentioned in this advisory; it is a standard vendor patch notification distributed through CERT-FR.

Mentioned in this report

Vulnerabilities CVE-2026-18125CVE-2026-18127CVE-2026-18129

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1007

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free