CVE-2026-8043Patch(ivanti / xtraction)

MEDIUMCVSS 9.6 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Patch ivanti xtraction systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • xtraction

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 14 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 9 signals
  • Technical details provided in 14 signals
  • Disclosure: 4 classified signals
  • Peaked 3d ago at 4 mentions (2026-05-18); latest day: 1
  • 14 total mentions across 7 days

Affected systems

Vendors
Products
xtraction

Deep dive

Activity timeline14 mentions / 7d
01234Mentions · 2026-05-12: 2Mentions · 2026-05-13: 1Mentions · 2026-05-14: 2Mentions · 2026-05-18: 4Mentions · 2026-05-19: 2Mentions · 2026-05-20: 2Mentions · 2026-05-24: 1Active Exploitation · 2026-05-18: 1Patch / Workaround · 2026-05-13: 1Patch / Workaround · 2026-05-14: 2Patch / Workaround · 2026-05-18: 3Patch / Workaround · 2026-05-19: 1Patch / Workaround · 2026-05-20: 2Technical Details · 2026-05-12: 2Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 2Technical Details · 2026-05-18: 4Technical Details · 2026-05-19: 2Technical Details · 2026-05-20: 2Technical Details · 2026-05-24: 105-1205-1305-1405-1805-1905-2005-24
Signal classification4 categories
Patch
857.1%
Disclosure
428.6%
Active Exploitation
17.1%
General
17.1%
Referenced assets16 URLs
Classification over time
DateTotalLabels
2026-05-122
Disclosure2
2026-05-131
Disclosure1
2026-05-142
Patch2
2026-05-184
Active Exploitation1Patch3
2026-05-192
General1Patch1
2026-05-202
Patch2
2026-05-241
Disclosure1
Full discourse14 posts
  • Gray Hats@the_yellow_fall
    Patch

    Ivanti issues an urgent patch for CVE-2026-8043, a critical 9.6 CVSS flaw in Xtraction allowing attackers to read files and write malicious HTML. Update now! #Ivanti #CyberSecurity #InfoSec #VulnerabilityAlert #CVE #DataSecurity #PatchManagement #TechNews https://securityonline.info/ivanti-xtraction-vulnerability-cve-2026-8043-critical-flaw/ https://t.co/0F675EYgfa

    Post summary

    Ivanti has released an urgent patch for the CVE‑2026‑8043 critical flaw in Xtraction, which allows attackers to read files and write malicious HTML; immediate update is advised.

    13042660
    12.5K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple critical and high vulnerabilities in #Ivanti #EndpointManager #EPM #VirtualTrafficManager #VTM #Xtraction #CVE-2026-8043 #CVE-2026-8051 #CVE-2026-8111 #CVE-2026-8110 CVSS: 9.6.-7.2 For details visit our advisory https://ccb.belgium.be/advisories/warning-ivanti-has-released-security-updates-address-vulnerabilities-affecting-several #Patch #Patch #Patch

    Post summary

    The post announces that Ivanti has issued security updates addressing several critical vulnerabilities identified by CVEs, providing CVSS scores and directing readers to an advisory for patch details.

    02010247
    7.2K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    2026年5月ぱっちちゅーずでーまとめ ◆Microsoft https://www.microsoft.com/en-us/msrc/blog/2026/05/202605-security-update CVE-2026-42898 Microsoft Dynamics 365 オンプレミスのリモートでコードが実行される脆弱性 CVE-2026-42823 Azure Logic Apps の特権昇格の脆弱性 CVE-2026-41096 Windows DNS クライアントのリモートでコードが実行される脆弱性 CVE-2026-41089 Windows Netlogon のリモートでコードが実行される脆弱性 ◆Ivanti https://www.ivanti.com/blog/may-2026-security-update critical1件 ■CVE-2026-8043(Critical) ファイル名制御不備により認証済ユーザが任意ファイル読取・HTML書込可能。情報漏えいに加え、XSS等のクライアント攻撃や踏み台化の恐れ ◆Fortinet https://fortiguard.fortinet.com/psirt critical2件 ■CVE-2026-26083(FortiSandbox / 認証不要RCE) 認可不備により未認証攻撃者がHTTPリクエスト経由で任意コード実行可能。ネットワーク越し・認証不要で悪用可能なため侵害難易度が低く、最優先でのパッチ適用が必要。 ■CVE-2026-44277(FortiAuthenticator / 認証不要RCE) APIのアクセス制御不備により未認証攻撃者が任意コマンド実行可能。IAM基盤への侵害に直結し、認証・証明書管理を含む全体統制を破壊するリスクが高い。 ◆SAP SAP Security Patch Day - January 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/january-2026.html critical4件 ■ CVE-2026-0501(SQL Injection:S/4HANA) 外部入力の検証不備によりSQLインジェクションが成立し、DBの機密情報取得・改ざん・削除が可能。業務データへの直接影響が大きい。認証済ユーザ(業務ユーザ等)でも悪用可能なケースが想定され、権限逸脱型リスクが高い。 ■ CVE-2026-0500(RCE:Wily Introscope) 細工されたリクエストにより任意コード実行が可能となる脆弱性。監視基盤の乗っ取りや横展開の踏み台となる危険がある。認証不要または低権限でも悪用できる可能性があり、外部攻撃者・内部第三者双方に対して高リスク。 ■ CVE-2026-0498(Code Injection:S/4HANA) 入力処理不備を突いたコードインジェクションにより、アプリケーション処理の改ざんや不正実行が可能。業務アプリ経由で実行されるため、正規ユーザ(認証済第三者)による悪用や、意図しない権限範囲での操作に繋がるリスクが高い。 ■ CVE-2026-0491(Code Injection:Landscape Transformation) データ移行・統合処理におけるコードインジェクションにより、システム改ざんやデータ破壊が可能。移行作業や連携処理を扱う認証済ユーザから悪用される可能性があり、内部・委託先など第三者経由での被害拡大が懸念。 ◆Adobe https://helpx.adobe.com/security.html critical4件 ■CVE-2026-34659(Adobe Connect / RCE) デシリアライズ不備により未認証攻撃者が細工データを通じて任意コード実行可能。ユーザ操作誘導で成立し、CVSS9.6の極めて高リスク脆弱性。 ■CVE-2026-34660(Adobe Connect / 権限昇格) 認可不備により権限昇格が可能。RCEと組み合わせることで完全な環境乗っ取りに発展する恐れがあり、Connect系の中でも特に影響大。 ■CVE-2026-34653(Adobe Commerce / パストラバーサル) ディレクトリ操作不備により任意ファイル書込みが可能。攻撃者によるサーバ改ざん・Webシェル設置に繋がる恐れがある重大リスク。 ■CVE-2026-34686(Adobe Commerce / XSS→RCE) 保存型XSSにより任意スクリプト実行が可能。管理画面等と組み合わせるとコード実行やセッション奪取等の高リスク攻撃に発展。

    Post summary

    The text announces a series of new CVEs with technical details and associated vendor patch notifications, focusing on disclosure of vulnerabilities rather than exploitation or patch instructions.

    000211.4K
    11.7K followersView on X
  • ThaiCERT By NCSA@ThaiCERTByNCSA
    Patch

    🛑 แจ้งเตือนช่องโหว่ร้ายแรงใน Ivanti Xtraction เสี่ยงข้อมูลรั่วไหลและถูกฝังไฟล์ HTML อันตราย ศูนย์ประสานการรักษาความมั่นคงปลอดภัยระบบคอมพิวเตอร์แห่งชาติ (ThaiCERT) ได้ติดตามสถานการณ์ข่าวสารภัยคุกคามทางไซเบอร์ และพบรายงานเกี่ยวกับช่องโหว่ใน Ivanti Xtraction หมายเลข CVE-2026-8043 ให้ผู้ใช้งานเร่งตรวจสอบและอัปเดตระบบ หลัง Ivanti เผยแพร่อัปเดตเพื่อแก้ไขช่องโหว่ 1. รายละเอียดช่องโหว่ [1] ช่องโหว่ CVE-2026-8043 (CVSS v3.1: 9.6)[2] เกิดจากการควบคุมชื่อไฟล์หรือพาธไฟล์จากภายนอกไม่เหมาะสม หรือ External Control of File Name or Path (CWE-73) อาจทำให้ผู้โจมตีที่ผ่านการยืนยันตัวตนในระบบแล้ว สามารถอ่านไฟล์สำคัญภายในระบบ และเขียนไฟล์ HTML ไปยัง Web Directory ได้ ส่งผลให้ข้อมูลสำคัญอาจถูกเปิดเผย และอาจถูกนำไปใช้ในการโจมตีผู้ใช้งานผ่านฝั่งเบราว์เซอร์ เช่น การสร้างหน้าเว็บหลอกลวง หรือการฝังเนื้อหาอันตรายบนหน้าเว็บที่ผู้ใช้เข้าถึง 2. ผลิตภัณฑ์ที่ได้รับผลกระทบ - Ivanti Xtraction เวอร์ชัน 2026.1 และก่อนหน้า 3. แนวทางการป้องกันและแก้ไข 3.1 อัปเดต Ivanti Xtraction เป็นเวอร์ชัน 2026.2 หรือใหม่กว่า ตามคำแนะนำของ Ivanti 3.2 ตรวจสอบเวอร์ชันของ Ivanti Xtraction ที่ใช้งาน เพื่อประเมินว่าระบบอยู่ในเวอร์ชันที่ได้รับผลกระทบหรือไม่ 3.3 ตรวจสอบบัญชีผู้ใช้งานภายในระบบ โดยเฉพาะบัญชีที่มีสิทธิ์เข้าถึงข้อมูลสำคัญหรือสามารถจัดการไฟล์ได้ 3.4 ลดสิทธิ์ของบัญชีผู้ใช้งานให้เหลือเท่าที่จำเป็น ตามหลัก Least Privilege และยกเลิกบัญชีที่ไม่จำเป็นหรือไม่ได้ใช้งานแล้ว 3.5 ตรวจสอบ Log ที่เกี่ยวข้องกับการอ่านไฟล์ การสร้างไฟล์ และการแก้ไขไฟล์ใน Web Directory เพื่อค้นหาพฤติกรรมผิดปกติที่อาจเกี่ยวข้องกับการใช้ประโยชน์จากช่องโหว่ 3.6 เฝ้าระวังพฤติกรรมผิดปกติ เช่น การเข้าถึงไฟล์นอกขอบเขตปกติ การสร้างไฟล์ HTML ที่ไม่ทราบที่มา หรือการเข้าใช้งานจาก IP Address ที่ไม่คุ้นเคย 4. มาตรการลดความเสี่ยงหากยังไม่สามารถอัปเดตได้ทันที 4.1 จำกัดการเข้าถึง Ivanti Xtraction ให้เฉพาะผู้ใช้งานและเครือข่ายที่จำเป็นเท่านั้น 4.2 หากระบบเปิดให้เข้าถึงจากอินเทอร์เน็ต ควรจำกัดการเข้าถึงผ่าน VPN, เครือข่ายภายใน หรือระบบควบคุมการเข้าถึงที่เหมาะสม 4.3 บังคับใช้การยืนยันตัวตนหลายปัจจัย หรือ MFA สำหรับบัญชีที่เกี่ยวข้องกับระบบ 4.4 ตรวจสอบและลดสิทธิ์ของบัญชีผู้ใช้ที่ไม่จำเป็น หรือบัญชีที่มีสิทธิ์สูงเกินความจำเป็น 4.5 เฝ้าระวังการเข้าถึงไฟล์ การสร้างไฟล์ หรือการแก้ไขไฟล์ใน Web Directory อย่างใกล้ชิด 4.6 ตรวจสอบไฟล์ HTML หรือไฟล์เว็บที่ไม่ทราบที่มา หากพบควรตรวจสอบทันที 4.7 เก็บหลักฐาน Log ที่เกี่ยวข้อง เพื่อใช้ในการวิเคราะห์เหตุการณ์หากพบพฤติกรรมต้องสงสัย แหล่งอ้างอิง [1] https://dg.th/va76jztdhr [2] https://dg.th/ntxed8ch4s

    Post summary

    ThaiCERT alerts users to CVE‑2026‑8043, a critical file‑path control flaw in Ivanti Xtraction, and urges immediate patching to version 2026.2 or newer along with recommended mitigations.

    01010123
    54 followersView on X
  • connect24h@connect24h
    Patch

    であえーであえー。🚨 主要インフラ4社が同日RCEパッチを一斉リリース Ivanti / Fortinet / SAP / VMwareが認証バイパス・RCE・権限昇格を同時修正。最深刻はIvanti Xtraction(CVE-2026-8043、CVSS 9.6)。CSIRTは即時対応必須。 https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html #CSIRT #Security

    Post summary

    Several major vendors released patches addressing authentication bypass, RCE, and privilege escalation flaws, with the most critical being Ivanti Xtraction CVE‑2026‑8043 (CVSS 9.6).

    00002221
    2.8K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - Ivanti Xtraction Arbitrary File Read via External File Name Control (CVE-2026-8043) Ivanti Xtraction before version 2026.2 contains an external control of file name or path vulnerability. A remote authenticated attacker can exploit this flaw to read arbitrary sensitive files on the server. This can lead to exposure of confidential data, credentials, or other sensitive information. 👉Affected: Ivanti Xtraction < 2026.2

    Post summary

    The tweet announces the discovery of a critical arbitrary file read vulnerability (CVE-2026-8043) in Ivanti Xtraction, detailing affected versions and the potential impact, but does not provide PoC, exploit, patch, or evidence of active exploitation.

    00020116
    187 followersView on X
  • AI Security Gateway@AISGateway
    General

    🔒CVE-2026-8043 (CVSS 9.6) in Ivanti Xtraction is a reminder: your enterprise attack surface now includes every AI workflow that touches those systems. When infra gets pwned, LLM integrations are data exfiltration routes you may not be watching.

    Post summary

    The post highlights the high CVSS score of CVE-2026-8043 and warns that AI workflow integration increases attack surface, but it offers no PoC, exploit code, patch info, or evidence of real‑world attacks.

    1000054
    39 followersView on X
  • TodayInCyber@TodayInCyberIO
    Patch

    2/5 Ivanti Xtraction (CVE-2026-8043): a critical flaw enabling information disclosure and client-side attacks. Patch released. Fortinet FortiAuthenticator and FortiSandbox (CVE-2026-44277, CVE-2026-26083): critical vulnerabilities enabling remote code execution.

    Post summary

    The post announces critical vulnerabilities for Ivanti Xtraction and Fortinet products with patch releases, but does not mention any PoC, exploit tools, or active exploitation.

    100003
    8 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-8043: External Control of File Name in Ivanti Xtraction - What It Means for Your Business and How to Respond https://hubs.li/Q04hLXsD0

    Post summary

    The statement announces a newly identified Ivanti Xtraction vulnerability (CVE‑2026‑8043) involving externally controllable file names, but offers no PoC, exploit, or patch details.

    0000049
    31 followersView on X
  • isogashii@cyber_risk_sec
    Patch

    3. Ivanti Xtraction CVE-2026-8043(CVSS 9.6) 機密ファイルの読み取りと任意HTMLファイルの書き込みが可能。バージョン2026.2未満が対象。リモート認証済み攻撃者がクライアントサイド攻撃と情報漏えいを引き起こせる。パッチ公開済み・即時適用推奨。原典: https://thehackernews.com/

    Post summary

    Ivanti Xtraction CVE-2026-8043 allows authenticated attackers to read confidential files and write arbitrary HTML, carrying a CVSS score of 9.6; a patch has already been released and should be applied immediately.

    0000065
    121 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2026-8043: Ivanti Xtraction Critical Flaw and Multi-Vendor Patch Advisory "Critical patches for Ivanti Xtraction, Fortinet, and others address RCE and auth bypass." 🔗 https://securityarsenal.com/blog/cve-2026-8043-ivanti-xtraction-critical-flaw-and-multi-vendor-patch-advisory #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    The text is a patch advisory announcing critical fixes for Ivanti Xtraction and Fortinet, addressing RCE and authentication bypass, with no exploit or PoC details provided.

    0000076
    16 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers exploiting CVE-2026-8043 in Ivanti Xtraction can escalate privileges and move laterally within networks after initial file disclosure. TRC analysis shows the CVSS 9.6 vulnerability enables complete attack chains from sensitive file access to operational disruption. Runtime segmentation helps contain such post-compromise lateral movement. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/ivanti-xtraction-cve-2026-8043

    Post summary

    The report confirms that attackers are actively exploiting CVE‑2026‑8043 in Ivanti Xtraction for privilege escalation and lateral movement, with a CVSS score of 9.6.

    0000051
    1.9K followersView on X
  • Systemctl@TheNetworkGhost
    Patch

    🚨 Araç: Ivanti, Fortinet, SAP, VMware, n8n Kritik Açıklar Yamalandı 📅 18 Mayıs 2026 · 13:54 (TR) Ivanti Xtraction'daki kritik bir açık (CVE-2026-8043, CVSS 9.6) başta olmak üzere, Fortinet, SAP, VMware ve n8n ürünlerinde kimlik doğrulama atlatma ve rastgele kod çalıştırma gibi ciddi güvenlik açıkları tespit edildi. Bu zafiyetler, saldırganların sistemlere sızarak bilgi ifşası veya istemci tarafı saldırılar gerçekleştirmesine olanak tanıyabilir. Tüm kullanıcıların, etkilenen ürünler için yayınlanan güvenlik yamalarını derhal yüklemesi büyük önem taşımaktadır. https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html #SiberGüvenlik #CyberSecurity #SysAdmin #Network #Infosec #Hacking #Haber #18Mayıs Kaynak: http://thehackernews.com

    Post summary

    Makale, birden fazla üreticinin kritik açığını bildiriyor ve acilen yayımlanan yamaların kurulumunu çağırıyor; PoC, exploit veya canlı saldırı bilgisi bulunmuyor.

    0000011
    78 followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-8043 External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to rea… CVSS 9.6 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-8043 #Ivanti #CyberSecurity #InfoSec

    Post summary

    CVE-2026-8043 is a critical vulnerability in Ivanti Xtraction allowing remote authenticated attackers to exploit uncontrolled file names (CVSS 9.6); no patch has been released yet.

    0000037
    90 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appivantixtraction---

Explore more