Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical RCE in Ivanti Xtraction (CVE‑2026‑8043) and Related Flaws Across Fortinet, SAP, VMware, n8n Threaten Enterprise Supply Chains

A wave of high‑severity vulnerabilities—including a CVSS 9.6 remote code execution in Ivanti Xtraction—has been disclosed across five major vendors. Exploits are already circulating, putting enterprises that rely on these products at risk of data loss, service disruption, and supply‑chain compromise.

LiveThreat™ Intelligence · 📅 May 18, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
4 sector(s)
✅
Actions
5 recommended
📰
Source
thehackernews.com

Critical RCE in Ivanti Xtraction (CVE‑2026‑8043) and Related Flaws Across Fortinet, SAP, VMware, n8n Threaten Enterprise Supply Chains

What It Is — A set of high‑severity vulnerabilities disclosed in May 2026 affect Ivanti Xtraction (CVE‑2026‑8043, CVSS 9.6), Fortinet firewalls, SAP applications, VMware virtualization platforms, and the n8n workflow automation tool. The flaws enable authentication bypass, remote code execution, SQL injection, and privilege escalation.

Exploitability — Proof‑of‑concept exploits for the Ivanti RCE have been published; other vendor patches were released pre‑emptively, indicating active threat interest. CVSS scores range from 7.8 to 9.6.

Affected Products — Ivanti Xtraction, Fortinet FortiGate/FortiOS, SAP NetWeaver, VMware vSphere/ESXi, n8n open‑source automation.

TPRM Impact — Compromise of any of these products can cascade through downstream services, exposing data, disrupting operations, and eroding trust in third‑party vendors that many organizations rely on for endpoint management, network security, ERP, cloud infrastructure, and workflow automation.

Recommended Actions –

  • Verify that the latest security patches from each vendor are applied within 48 hours.
  • Conduct immediate vulnerability scans on all assets running the listed products.
  • Review and tighten network segmentation to limit lateral movement from potentially compromised components.
  • Update third‑party risk registers to reflect the new CVE and re‑assess vendor risk scores.
  • Monitor threat intel feeds for exploit activity targeting these CVEs.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →