Ivanti Security Update – 15 July 2026

Ivanti has released a security update to fix two vulnerabilities affecting Ivanti Xtraction.

The addressed vulnerabilities could allow the remote authenticated attacker to redirect users to arbitrary external URLs or obtain sensitive information from the affected product.

Sample of the addressed vulnerabilities:

Ivanti Xtraction Path Traversal Vulnerability (CVE-2026-14903):

  • CVSS: 7.7
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Obtain Information
Vulnerabilities
  • CVE-2026-14903
  • CVE-2026-14902
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Ivanti Security Advisory

References