CVE-2026-18125: High severity vulnerability
An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ivanti Endpoint Manager Agentto a version that resolves this vulnerability.Fixed in 2024 SU7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18125?
The severity of CVE-2026-18125 is classified as high with a CVSS score of 7.5.
What are the risks associated with CVE-2026-18125?
CVE-2026-18125 poses a risk of remote unauthenticated attackers crashing the agent service due to an out-of-bounds read.
How do I fix CVE-2026-18125?
To fix CVE-2026-18125, upgrade to Ivanti Endpoint Manager version 2024 SU7 or later.
What should I do if I am affected by CVE-2026-18125?
If affected by CVE-2026-18125, apply the recommended patch from Ivanti as soon as possible.
Can CVE-2026-18125 affect my organization?
Yes, CVE-2026-18125 can affect your organization if you are using a vulnerable version of Ivanti Endpoint Manager.