Every CVE whose affected-product data names Ivanti Xtraction, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (3)
CVE-2026-8043 — CVSS 9.6 (critical): External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files…
CVE-2026-14903 — CVSS 7.7 (high): Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web…
CVE-2026-14902 — CVSS 4.0 (medium): An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary…