Ivanti Xtraction CVE-2026-8043 Vulnerability Fixed in Latest Security Patch
Patch Ivanti Xtraction to fix CVE-2026-8043 and other vendor fixes.
Apply the Ivanti Xtraction patch immediately to eliminate the authentication bypass.
Summary
Ivanti, along with Fortinet, n8n, SAP, and VMware, released security fixes for various vulnerabilities that could be exploited to bypass authentication and execute arbitrary code. The critical flaw in Ivanti Xtraction, identified as CVE-2026-8043, allows attackers to bypass authentication and achieve arbitrary code execution. The vulnerability carries a CVSS score of 9.6 and exploits external control of a file name to gain elevated privileges. Other vendors also addressed similar issues in their latest patches. The security update is now available and should be applied immediately to mitigate the risk. Administrators using Ivanti Xtraction must update their systems to protect against this high‑severity flaw.
Key changes
- Ivanti Xtraction CVE-2026-8043 authentication bypass flaw
- CVSS score 9.6
- Allows arbitrary code execution
- External control of file name exploited
- Other vendors (Fortinet, n8n, SAP, VMware) also released fixes
- Critical security update available
- Must patch immediately