Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-49435: Keysight IxChariot products allow unauthorized code execution
CVE-2026-49435
CVE-2026-49435
Summary
Keysight's IxChariot Endpoint and associated products are affected. An attacker can send a malicious packet to gain full control of the system, which could lead to data theft or system compromise. Users should update to the latest version to fix this vulnerability.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| keysight | hawkeye | < 6.0.7 |
| keysight | ixchariot | < 10.0.254 |
| keysight | ixtap | < 3.13.0 |
| keysight | ixprobe | < 3.13.0 |
| keysight | ixbypass | < 3.13.0.69 |
Original title
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with adm...
Original description
Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.
mitre CVSS3.1
9.8
Vulnerability type
CWE-121
Stack-based Buffer Overflow
- https://www.keysight.com/us/en/lib/software-detail/computer-software/hawkeye.htm... release-notes
- https://www.keysight.com/us/en/about/quality-and-security/security/product-and-s... release-notes
- https://www.keysight.com/us/en/lib/software-detail/computer-software/ixchariot.h... release-notes
- https://www.keysight.com/us/en/lib/software-detail/instrument-firmware-software/... release-notes
- https://www.keysight.com/us/en/product/IXTP-CU3-T/copper-taps---ixtp-cu3-t.html release-notes
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/... third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2026-49435 vdb-entry
Published: 4 Aug 2026 · Updated: 5 Aug 2026 · First seen: 4 Aug 2026