CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Critical RCE, SQL Injection, and Privilege Escalation Flaws Patched in Ivanti, Fortinet, SAP, VMware, and n8n

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Multiple vendors have released critical security updates addressing remote code execution (RCE), SQL injection, and privilege escalation vulnerabilities across enterprise software and infrastructure. Ivanti patched an authentication bypass flaw in Xtraction (CVE-2026-8043, CVSS 9.6) enabling file read/write to disclose sensitive data. Fortinet resolved two critical issues in FortiAuthenticator (CVE-2026-44277, CVSS 9.1) and FortiSandbox (CVE-2026-26083, CVSS 9.1) allowing unauthenticated RCE. SAP fixed a critical SQL injection flaw in S/4HANA (CVE-2026-34260, CVSS 9.6) and a missing authentication check in SAP Commerce (CVE-2026-34263, CVSS 9.6) enabling server-side code execution. VMware addressed a TOCTOU flaw in Fusion (CVE-2026-41702, CVSS 7.8) permitting local privilege escalation to root. n8n issued fixes for five prototype pollution and CLI injection flaws (CVSS 9.4) enabling authenticated RCE in workflow automation platforms. Exploitation of these flaws could lead to full system compromise, data exfiltration, or lateral movement in enterprise environments.

Timeline

  1. 18.05.2026 13:54 1 articles · 17h ago

    Critical RCE and Privilege Escalation Flaws Patched Across Multiple Enterprise Platforms

    Ivanti addressed CVE-2026-8043 (CVSS 9.6) in Xtraction, allowing authenticated attackers to read/write files via external file name control. Fortinet resolved CVE-2026-44277 (CVSS 9.1) in FortiAuthenticator and CVE-2026-26083 (CVSS 9.1) in FortiSandbox and related services, both enabling unauthenticated RCE. SAP patched CVE-2026-34260 (CVSS 9.6), an SQL injection flaw in S/4HANA, and CVE-2026-34263 (CVSS 9.6), a missing authentication check in SAP Commerce enabling server-side code execution. VMware issued fixes for CVE-2026-41702 (CVSS 7.8) in Fusion, a TOCTOU flaw allowing local privilege escalation to root. n8n released patches for five critical flaws (CVSS 9.4) including prototype pollution and CLI injection vectors enabling authenticated RCE in workflow automation platforms.

    Show sources

Information Snippets