Upwind Security MDR[verified]@UpwindMDRPatch
Ivanti’s August 2026 advisory discloses three CVEs with technical details and CVSS scores, and recommends applying the 2024 SU7 patch to remediate the vulnerabilities.
Kaitan ID Security[verified]@KaitanSecurityDisclosure
This is a high‐severity disclosure of CVE-2026-18129, detailing cleartext transmission of sensitive data in Ivanti Endpoint Manager pre‑2024 SU7, with a CVSS score of 8.1 and a link to an analysis but no PoC, exploit, or patch yet.
The Daily Tech Feed[verified]@dailytechonxDisclosure
Ivanti’s Endpoint Manager has disclosed critical CVEs that may allow remote attackers to crash services, manipulate cloud storage, and intercept data, with users urged to apply the 2024 SU7 update immediately.
DC3 DCISE@DC3DCISEPatch
The tweet highlights Ivanti EPM vulnerabilities (CVE-2026-18129/18127/18125) that can leak SQL credentials, grant S3 write access, or crash services, and urges immediate upgrade to EPM 2024 SU7.
CCB Alert@CCBalertPatch
The tweet announces high‑severity vulnerabilities in IvantiEPM, lists CVE identifiers with CVSS scores and potential impacts, and encourages patching.
Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56Disclosure
CVE-2026-18129 is a cleartext transmission vulnerability that allows credential leakage via MitM; no PoC, exploit tools, or active exploitation are reported.