CVE-2026-18129Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 3 mentions (2026-08-11); latest day: 1
  • 6 total mentions across 4 days

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-08-11: 3Mentions · 2026-08-12: 1Mentions · 2026-08-17: 1Mentions · 2026-09-16: 1Patch / Workaround · 2026-08-11: 2Patch / Workaround · 2026-08-17: 1Patch / Workaround · 2026-09-16: 1Technical Details · 2026-08-11: 3Technical Details · 2026-08-12: 1Technical Details · 2026-08-17: 1Technical Details · 2026-09-16: 108-1108-1208-1709-16
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-113
Disclosure2Patch1
2026-08-121
Disclosure1
2026-08-171
Patch1
2026-09-161
Patch1
Full discourse6 posts
  • DC3 DCISE@DC3DCISE
    Patch

    #DCISEWarning: Ivanti EPM Vulnerabilities Theat: Flaws in EPM 2024 SUG & prior (CVE-2026-18129/18127/18125) leak SQL credentials, grant full S3 bucket write control, or crash agent services. Action: Upgrade affected Ivanti EPM systems to 2024 SU7 now. https://t.co/b3lBG1Lv2W

    Post summary

    The tweet highlights Ivanti EPM vulnerabilities (CVE-2026-18129/18127/18125) that can leak SQL credentials, grant S3 write access, or crash services, and urges immediate upgrade to EPM 2024 SU7.

    110201.2K
    738 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High severity flaws in #IvantiEPM: #CVE-2026-18125 CVSS:7.5, #CVE-2026-18127 CVSS:7.7, and #CVE-2026-18129 CVSS:8.1. Risks include agent crashes, S3 bucket takeover, and MITM credential leaks. #Patch #Patch #Patch

    Post summary

    The tweet announces high‑severity vulnerabilities in IvantiEPM, lists CVE identifiers with CVSS scores and potential impacts, and encourages patching.

    00000273
    7.2K followersView on X
  • Jeff Hall - PCI Guru - #StandWithUkraine@jbhall56
    Disclosure

    Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. https://www.securityweek.com/ivanti-epm-update-patches-remotely-exploitable-flaws/

    Post summary

    CVE-2026-18129 is a cleartext transmission vulnerability that allows credential leakage via MitM; no PoC, exploit tools, or active exploitation are reported.

    0000051
    912 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - Ivanti Endpoint Manager Fixes Three Vulnerabilities in August 2026 (CVE-2026-18125 / 18127 / 18129) Ivanti's August 2026 EPM advisory addresses three separate issues, all fixed in 2024 SU7: - CVE-2026-18125 (7.5): an out-of-bounds read in the Agent lets a remote unauthenticated attacker crash the agent service (denial of service). - CVE-2026-18127 (7.7): external control of a filename in the Core gives a remote authenticated low-privilege attacker full write control over the S3 bucket used for session-recording storage. - CVE-2026-18129 (8.1): improper certificate validation in the Core lets an unauthenticated attacker in a man-in-the-middle position leak credentials for external SQL connections. None are unauthenticated RCE, but given Ivanti's history of active exploitation, patching promptly is worthwhile. 👉Upgrade Ivanti Endpoint Manager to 2024 SU7.

    Post summary

    Ivanti’s August 2026 advisory discloses three CVEs with technical details and CVSS scores, and recommends applying the 2024 SU7 patch to remediate the vulnerabilities.

    0000062
    285 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-18129 Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a… CVSS 8.1 Full analysis → https://sec.kaitan.id/cves/CVE-2026-18129 #Ivanti #CyberSecurity #InfoSec

    Post summary

    This is a high‐severity disclosure of CVE-2026-18129, detailing cleartext transmission of sensitive data in Ivanti Endpoint Manager pre‑2024 SU7, with a CVSS score of 8.1 and a link to an analysis but no PoC, exploit, or patch yet.

    0000041
    88 followersView on X
  • The Daily Tech Feed@dailytechonx
    Disclosure

    Ivanti's Endpoint Manager software has disclosed critical vulnerabilities, including CVE-2026-18125, CVE-2026-18127, and CVE-2026-18129. These flaws could allow remote attackers to crash services, manipulate cloud storage, and intercept sensitive data. Organizations are urged to update to EPM 2024 SU7 immediately to mitigate these risks. #Ivanti #EndpointManager #Cybersecurity #Vulnerabilities #SecurityUpdate #DataProtection https://thedailytechfeed.com/ivanti-endpoint-manager-vulnerabilities-expose-systems-to-remote-attacks/

    Post summary

    Ivanti’s Endpoint Manager has disclosed critical CVEs that may allow remote attackers to crash services, manipulate cloud storage, and intercept data, with users urged to apply the 2024 SU7 update immediately.

    0000057
    626 followersView on X

Explore more