CVE-2026-18127Patch

LOWCVSS 7.7 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-11); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-11: 3Mentions · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-11: 1Patch / Workaround · 2026-08-11: 2Patch / Workaround · 2026-08-17: 1Technical Details · 2026-08-11: 2Technical Details · 2026-08-17: 108-1108-17
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-113
Disclosure1Patch2
2026-08-171
Patch1
Full discourse4 posts
  • CCB Alert@CCBalert
    Patch

    Warning: High severity flaws in #IvantiEPM: #CVE-2026-18125 CVSS:7.5, #CVE-2026-18127 CVSS:7.7, and #CVE-2026-18129 CVSS:8.1. Risks include agent crashes, S3 bucket takeover, and MITM credential leaks. #Patch #Patch #Patch

    Post summary

    The post alerts users to three high‑severity vulnerabilities in IvantiEPM, citing CVSS scores and potential impacts, and urges patching.

    00000273
    7.2K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - Ivanti Endpoint Manager Fixes Three Vulnerabilities in August 2026 (CVE-2026-18125 / 18127 / 18129) Ivanti's August 2026 EPM advisory addresses three separate issues, all fixed in 2024 SU7: - CVE-2026-18125 (7.5): an out-of-bounds read in the Agent lets a remote unauthenticated attacker crash the agent service (denial of service). - CVE-2026-18127 (7.7): external control of a filename in the Core gives a remote authenticated low-privilege attacker full write control over the S3 bucket used for session-recording storage. - CVE-2026-18129 (8.1): improper certificate validation in the Core lets an unauthenticated attacker in a man-in-the-middle position leak credentials for external SQL connections. None are unauthenticated RCE, but given Ivanti's history of active exploitation, patching promptly is worthwhile. 👉Upgrade Ivanti Endpoint Manager to 2024 SU7.

    Post summary

    Ivanti’s advisory lists three CVEs with technical details and urges users to apply the 2024 SU7 patch to mitigate potential denial-of-service and privilege escalation issues.

    0000062
    285 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-18127 External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authentic… CVSS 7.7 Full analysis → https://sec.kaitan.id/cves/CVE-2026-18127 #Ivanti #CyberSecurity #InfoSec

    Post summary

    A newly disclosed vulnerability (CVE‑2026‑18127) in Ivanti Endpoint Manager allows remote authenticated exploitation via external filename control, rated CVSS 7.7.

    0000039
    88 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Ivanti's Endpoint Manager software has disclosed critical vulnerabilities, including CVE-2026-18125, CVE-2026-18127, and CVE-2026-18129. These flaws could allow remote attackers to crash services, manipulate cloud storage, and intercept sensitive data. Organizations are urged to update to EPM 2024 SU7 immediately to mitigate these risks. #Ivanti #EndpointManager #Cybersecurity #Vulnerabilities #SecurityUpdate #DataProtection https://thedailytechfeed.com/ivanti-endpoint-manager-vulnerabilities-expose-systems-to-remote-attacks/

    Post summary

    Ivanti’s release discloses critical vulnerabilities in its Endpoint Manager and urges users to apply the 2024 SU7 patch to mitigate possible crashes, storage manipulation, and data interception.

    0000057
    626 followersView on X

Explore more