logo

Critical 9.6 Severity Ivanti Xtraction Flaw Exposes Sensitive Data

ID: 4ba2023a-af7c-5163-bfcd-5a67652b0798

STIX ID: report--4ba2023a-af7c-5163-bfcd-5a67652b0798

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-14

Date Updated: 2026-05-14

Author: Ddos

...
...

Ivanti issued an urgent advisory for CVE-2026-8043, a critical (CVSS 9.6) file-name control vulnerability in Ivanti Xtraction that permits remotely authenticated attackers to read sensitive internal files and drop arbitrary HTML into web directories (risking data exposure and client-side attacks); the issue affects 2026.1 and prior and is resolved in 2026.2 with a patch available, and the vendor reported no known customer exploitation at disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.