CVE-2026-18125Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-08-11); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-11: 3Mentions · 2026-08-17: 1Patch / Workaround · 2026-08-11: 2Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-11: 3Technical Details · 2026-08-17: 108-1108-17
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-113
Disclosure2Patch1
2026-08-171
Patch1
Full discourse4 posts
  • CCB Alert@CCBalert
    Patch

    Warning: High severity flaws in #IvantiEPM: #CVE-2026-18125 CVSS:7.5, #CVE-2026-18127 CVSS:7.7, and #CVE-2026-18129 CVSS:8.1. Risks include agent crashes, S3 bucket takeover, and MITM credential leaks. #Patch #Patch #Patch

    Post summary

    The message announces three high‑severity IvantiEPM vulnerabilities, provides CVSS scores and impact details, and stresses the importance of applying the patch.

    00000273
    7.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - Ivanti Endpoint Manager Fixes Three Vulnerabilities in August 2026 (CVE-2026-18125 / 18127 / 18129) Ivanti's August 2026 EPM advisory addresses three separate issues, all fixed in 2024 SU7: - CVE-2026-18125 (7.5): an out-of-bounds read in the Agent lets a remote unauthenticated attacker crash the agent service (denial of service). - CVE-2026-18127 (7.7): external control of a filename in the Core gives a remote authenticated low-privilege attacker full write control over the S3 bucket used for session-recording storage. - CVE-2026-18129 (8.1): improper certificate validation in the Core lets an unauthenticated attacker in a man-in-the-middle position leak credentials for external SQL connections. None are unauthenticated RCE, but given Ivanti's history of active exploitation, patching promptly is worthwhile. 👉Upgrade Ivanti Endpoint Manager to 2024 SU7.

    Post summary

    The advisory discloses three high‑severity vulnerabilities in Ivanti Endpoint Manager, details their technical nature, and urges users to patch to version 2024 SU7.

    0000062
    285 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-18125 An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated a… CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-18125 #Ivanti #CyberSecurity #InfoSec

    Post summary

    A high‑severity out‑of‑bounds read vulnerability (CVE‑2026‑18125) in Ivanti Endpoint Manager Agent (pre‑2024 SU7) permits remote unauthenticated exploitation, as detailed in a security analysis post; no exploit code, patch, or active exploitation is mentioned.

    0000039
    88 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    Ivanti's Endpoint Manager software has disclosed critical vulnerabilities, including CVE-2026-18125, CVE-2026-18127, and CVE-2026-18129. These flaws could allow remote attackers to crash services, manipulate cloud storage, and intercept sensitive data. Organizations are urged to update to EPM 2024 SU7 immediately to mitigate these risks. #Ivanti #EndpointManager #Cybersecurity #Vulnerabilities #SecurityUpdate #DataProtection https://thedailytechfeed.com/ivanti-endpoint-manager-vulnerabilities-expose-systems-to-remote-attacks/

    Post summary

    The post announces critical CVEs in Ivanti Endpoint Manager that could crash services, manipulate cloud data, and intercept sensitive information, and recommends immediate patching to EPM 2024 SU7.

    0000057
    626 followersView on X

Explore more