

Affected Environment
Ivanti Endpoint Manager before 2024 SU7 and Ivanti Neurons for MDM before release R124 on premise deployments.
Threat Overview
Multiple flaws allow unauthorized access, credential leakage, S3 bucket takeover, and cross tenant data exposure.
Exposure Timeline
Disclosed 11 August 2026; Ivanti released patched EPM 2024 SU7 and updated MDM cloud service.
Attack Surface
EPM Agent service, Core component session recording storage, and Neurons for MDM tenant data queries.
Technical Root Cause
Out of bounds read, external filename control, cleartext credential transmission, and improper query input neutralization.
Exploitation Pathway
Remote attacker crashes agent service, hijacks S3 storage, intercepts credentials via MITM, or queries cross tenant data.
Operational Impact
Agent crashes, data leakage, unauthorized S3 write access, and cross tenant information disclosure across managed endpoints.
Strategic Impact
Compromised endpoint management undermines device trust and can expose customer data across shared tenants.
Required Mitigation
Apply Ivanti Endpoint Manager 2024 SU7 immediately; confirm Neurons for MDM cloud tenants updated automatically.
Incident Response Guidance
Review agent crash logs, audit S3 bucket permissions, and rotate any exposed SQL credentials.
References
Ivanti Neurons for MDM Security Advisory
Ivanti Endpoint Manager Security Advisory
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




