ON
← Back to feed
Ivanti EPM: Update patches three high-risk security leaks
Germany🏛️ Politics6 days ago

Ivanti EPM: Update patches three high-risk security leaks

Ivanti, ein Softwarehersteller, hat Sicherheitsupdates für seine Endpoint Manager (EPM)-Software veröffentlicht, die drei hochkritische Sicherheitslücken beheben. Diese Lücken ermögachten Angreifern das Abgreifen von Zugangsdaten, Manipulation von Cloud-Speichern und Auslösung von Abstürzen im Agent-Dienst. Die Sicherheitsanfälligkeiten wurden als CVE-2026-18129, CVE-2026-18127 und CVE-2026-18115 identifiziert und erhalten jeweils einen hohen Risikowert. Ivanti bietet eine aktualisierte Version (EPM 2024 SU7 oder neuer) an, die diese Probleme behebt, und stellt sie im eigenen Lizenzsystem zum Download bereit. Der Hersteller berichtet bislang von keiner Nutzung dieser Schwachstellen durch Dritte, empfiehlt aber dringenden Einsatz der Updates, um die Sicherheit zu erhöhen.

Ivanti has released updates to its Endpoint Manager (EPM) software that address three high-risk security vulnerabilities, according to a security advisory published by the company. The patches close flaws that could allow attackers to intercept credentials, manipulate cloud storage, or cause the agent service to crash. The vulnerabilities were identified with Common Vulnerability and Exposure (CVE) identifiers CVE-2026-18129, CVE-2026-18127, and CVE-2026-18125, each carrying a high risk rating. The fixes are available in version EPM 2024 SU7 or later, which can be downloaded through Ivanti’s licensing system. The first vulnerability, CVE-2026-18129, allows attackers in a man-in-the-middle position to capture sensitive information transmitted in plaintext by the Ivanti EPM Core. This includes credentials for external SQL connections. The second flaw, CVE-2026-18127, enables unauthorized access to Amazon S3 buckets used for storing session recordings, granting full write permissions if an attacker provides a carefully crafted filename. The third issue, CVE-2026-18125, involves potential out-of-bounds memory access that unauthenticated attackers could exploit to trigger a denial-of-service condition by crashing the agent service. Ivanti did not provide detailed technical explanations of the flaws beyond confirming their existence and severity. The company stated that the updated software resolves these issues, though it emphasized that no exploitation of these vulnerabilities had been reported among its customers. As such, there are currently no known cases of successful attacks leveraging these specific weaknesses. Despite the recent patching efforts, Ivanti acknowledged that similar vulnerabilities were addressed earlier this year. In May, the company issued updates to fix flaws that allowed SQL injection and privilege escalation in vulnerable systems. These prior patches highlight a pattern of ongoing improvements to the EPM platform's security posture. IT administrators are advised to apply the latest updates promptly to reduce exposure to potential threats. While Ivanti has not observed any misuse of the newly patched vulnerabilities, the company urges users to take proactive steps in securing their environments. The recommendation aligns with best practices for maintaining cybersecurity resilience, especially given the critical role that endpoint management solutions play in enterprise networks. The release of these updates underscores the importance of timely software maintenance in mitigating emerging risks. With the increasing sophistication of cyber threats, organizations must remain vigilant and ensure that all systems are up-to-date with the latest security patches. Ivanti’s continued focus on addressing vulnerabilities demonstrates its commitment to supporting customer security, even as new threats continue to evolve.

Go to the primary sources (3)

The official sources this coverage is built on. Read them directly to bypass framing.

2 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 8010 days ago
Ivanti EPM: Update patches three high-risk security leaks

Ivanti, ein Softwarehersteller, hat Sicherheitsupdates für seine Endpoint Manager (EPM)-Software veröffentlicht, die drei hochkritische Sicherheitslücken beheben. Diese Lücken ermögachten Angreifern das Abgreifen von Zugangsdaten, Manipulation von Cloud-Speichern und Auslösung von Abstürzen im Agent-Dienst. Die Sicherheitsanfälligkeiten wurden als CVE-2026-18129, CVE-2026-18127 und CVE-2026-18115 identifiziert und erhalten jeweils einen hohen Risikowert. Ivanti bietet eine aktualisierte Version (EPM 2024 SU7 oder neuer) an, die diese Probleme behebt, und stellt sie im eigenen Lizenzsystem zum Download bereit. Der Hersteller berichtet bislang von keiner Nutzung dieser Schwachstellen durch Dritte, empfiehlt aber dringenden Einsatz der Updates, um die Sicherheit zu erhöhen.

Bias read (Center): Die Berichterstattung ist sachlich und informativ, ohne politischen Einfluss oder parteilichen Standpunkt. Es wird lediglich technische Sicherheitsaspekte behandelt, ohne Bewertung der politischen Konsequenzen oder Verantwortung von Regierungen oder Institutionen.

Why factuality (85): The article reports on Ivanti's release of updates addressing three high-risk security vulnerabilities in their EPM software. It cites specific CVE identifiers, CVSS scores, and risk levels, aligning with common cybersecurity reporting standards. The information appears consistent with typical vendo

Why objectivity (80): The tone remains professional and informative, focusing on technical details without overt bias. The article presents both the risks and the mitigation steps taken by Ivanti, though it emphasizes the importance of updating systems, which may subtly encourage prompt action.

heise online logoheise onlineIndependentCenterFactual 85Objective 756 days ago
Malware vulnerabilities are threatening PostgreSQL

Ein Sicherheitsupdate für das Datenbankmanagementsystem PostgreSQL hat mehrere Schwachstellen identifiziert, durch die Angreifer potenziell Schadcode ausführen könnten. Die Entwickler haben Versionen 14.24, 15.19, 16.15, 17.11 und 18.6 repariert. Der Support für PostgreSQL 14 endet am 12. November 2026, wodurch Sicherheitsupdates und -korrekturen nicht mehr bereitgestellt werden. Administratoren werden dringend gebeten, bis dahin ein Update auf eine weiterhin unterstützte Version vorzunehmen. Zwei spezifische Schwachstellen (CVE-2026-14662 und CVE-2026-18408) ermöglichen potenziell die Ausführung von Schadcode, allerdings sind bisher keine konkreten Angriffe bekannt.

Bias read (Center): Der Artikel berichtet objektiv über technische Sicherheitsaspekte eines Softwareprodukts ohne politischen Kontext oder parteiengesellschaftlicher Einordnung. Es wird keine politische Haltung vertreten oder bewerten, sondern lediglich Fakten zur Sicherheit von PostgreSQL mitgeteilt.

Why factuality (85): The article accurately reports that PostgreSQL 14.24, 15.19, 16.15, 17.11, and 18.6 have been updated to address 28 security vulnerabilities and over 110 bugs. It mentions the EOL date for PostgreSQL 14 and aligns with the primary source document. However, it omits some specific CVE identifiers and

Why objectivity (75): The tone is somewhat alarmist, suggesting that attackers can 'push and execute malicious code' and implying significant risk. While it presents facts neutrally, the phrasing leans toward emphasizing potential threats rather than providing a balanced view of the situation.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories