Ivanti released a security advisory for Ivanti Xtraction addressing two vulnerabilities affecting version 2026.2 and earlier: CVE-2026-14902, a medium-severity open redirect issue, and CVE-2026-14903, a high-severity path traversal flaw. Ivanti said the path traversal bug could allow an authenticated attacker to read arbitrary files outside the web root, while the open redirect issue could expose users to malicious redirection scenarios.
The vulnerabilities were fixed in Ivanti Xtraction 2026.2.1, and Ivanti said the issues were reported through its responsible disclosure program. The Canadian Centre for Cyber Security urged organizations to review Ivanti’s advisory and apply the necessary updates, while Ivanti said it was not aware of customer exploitation prior to public disclosure and directed customers to obtain the update through ILS.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On July 14, 2026, the Canadian Centre for Cyber Security published notice AV26-696 highlighting Ivanti's advisory for Ivanti Xtraction 2026.2 and prior. The notice urged users and administrators to review Ivanti's guidance and apply the necessary updates.
Ivanti stated that the vulnerabilities were fixed in Ivanti Xtraction version 2026.2.1 and advised customers to update via ILS. The fixes address an open redirect flaw and a high-severity path traversal issue that could let an authenticated attacker read arbitrary files outside the web root.
On July 14, 2026, Ivanti published a security advisory for CVE-2026-14902 and CVE-2026-14903 affecting Ivanti Xtraction 2026.2 and earlier. Ivanti said it was not aware of customer exploitation prior to public disclosure and that the issues were reported through its responsible disclosure program.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcecyber.gc.ca
Open sourcehub.ivanti.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.