Briefing

Ivanti Xtraction CVE-2026-8043 Vulnerability Fixed in Latest Security Patch

security
by [email protected] (The Hacker News) · CVE-2026-8043

Patch Ivanti Xtraction to fix CVE-2026-8043 and other vendor fixes.

What to do now

Apply the Ivanti Xtraction patch immediately to eliminate the authentication bypass.

Summary

Ivanti, along with Fortinet, n8n, SAP, and VMware, released security fixes for various vulnerabilities that could be exploited to bypass authentication and execute arbitrary code. The critical flaw in Ivanti Xtraction, identified as CVE-2026-8043, allows attackers to bypass authentication and achieve arbitrary code execution. The vulnerability carries a CVSS score of 9.6 and exploits external control of a file name to gain elevated privileges. Other vendors also addressed similar issues in their latest patches. The security update is now available and should be applied immediately to mitigate the risk. Administrators using Ivanti Xtraction must update their systems to protect against this high‑severity flaw.

Key changes

  • Ivanti Xtraction CVE-2026-8043 authentication bypass flaw
  • CVSS score 9.6
  • Allows arbitrary code execution
  • External control of file name exploited
  • Other vendors (Fortinet, n8n, SAP, VMware) also released fixes
  • Critical security update available
  • Must patch immediately

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting