Vulnerabilities · 50 days ago
Ivanti said in its August 2026 security update that it is disclosing vulnerabilities in Ivanti Neurons for MDM and Endpoint Manager (EPM). The company said it has no evidence of exploitation in the wild, and that the issues do not affect other Ivanti products.
Ivanti said it has added large language models (LLMs) to its product-security review process, alongside human verification, and that the system is finding issues traditional tools such as static and dynamic application security testing missed. In plain terms, the vendor expects its internal testing to surface more flaws, which should translate into more frequent advisories.
For operators of those products, the immediate change is the pace of disclosure, not an active incident. If your environment depends on Ivanti MDM or EPM, the vendor’s security notices may arrive more often as its review process matures.
3 sources covering this story
Ivanti EPM Update Patches Remotely Exploitable Flaws
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service.
Rilasciati gli aggiornamenti di sicurezza di agosto che risolvono 4 nuove vulnerabilità, di cui 3 con gravità “alta” nel prodotto Ivanti Endpoint Manager (EPM).
For the month of August 2026, Ivanti is disclosing vulnerabilities in Ivanti Neurons for MDM and Endpoint Manager (EPM).
Part of the PlainSec briefing for 2026-08-13