Out-of-Bounds Read Vulnerability in Ivanti Endpoint Manager
CVE-2026-18125

7.5HIGH

Key Information:

Vendor

Ivanti

Vendor
CVE Published:
11 August 2026

What is CVE-2026-18125?

An out-of-bounds read vulnerability in the Agent component of Ivanti Endpoint Manager allows a remote unauthenticated attacker to exploit this flaw, leading to potential crashes of the agent service. This issue highlights the need for organizations to quickly apply updates and patches to mitigate risks associated with unpatched software. It is crucial for users to monitor official advisories and maintain their systems updated to safeguard against similar vulnerabilities.

Affected Version(s)

Endpoint Manager 2024 SU7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.