What are you looking for?
Security Advisory: IxChariot Vulnerability
CVE-2026-49435, CVE-2017-20242, CVE-2017-20241
July 21, 2026
Overview
Keysight recently became aware of one critical (CVE-2026-49435) and two high severity (CVE-2017-20242, CVE-2017-20241) vulnerabilities at the IxChariot product code base.
The issues potentially allow full compromise of the target system through arbitrary code execution without any user interaction or privileges required.
If exploited, this vulnerability could allow a sophisticated attacker to execute code remotely. Keysight is not currently aware of malicious exploitation of the vulnerability and will continue to monitor the situation.
These issues were disclosed to Keysight by the Agence nationale de la sécurité des systèmes d'information (ANSSI) who reported them on behalf of Sébastien Charbonnier. Keysight would like to thank Sébastien Charbonnier and ANSSI for their assistance.
Issues CVE-2017-20242 and CVE-2017-20241 reported by the researcher were previously resolved by Keysight in 2017 as part of standard product maintenance. At that time, they were treated as functional defects rather than security vulnerabilities.
Impacted Products and Mitigation
We have assessed the complete Keysight product portfolio available as of this time and determined that, besides IxChariot, Hawkeye and some network probe products are also impacted by CVE-2026-494351.
Details and appropriate mitigation information can be found below:
| Vulnerability | Product | Mitigation |
|---|---|---|
| CVE-2017-20242 & CVE-2017-20241 | IxChariot Endpoint versions older than 9.5.102 | IxChariot Endpoint version 9.5.102 (released 11 August, 2017 as bug fixes) |
| CVE-2026-49435 | IxChariot Endpoint versions older than 10.0.254 | IxChariot Endpoint version 10.0.254 (released 30 April, 2026) |
| Hawkeye versions older than 6.0.7 | Hawkeye version 6.0.7 (released 26 June, 2026) | |
| IxProbe/IxTap/IxByPass versions older than 3.13.0 | IxProbe/IxTap/IxByPass version 3.13.0 (released 26 June, 2026) |
Recommended Action
Keysight recommends that all customers upgrade to the latest version of software as soon as possible. Older versions of software may have these vulnerabilities; we recommend that customers discontinue the use of older software versions.
In general, Keysight recommends that customers always follow industry cybersecurity best practices and always update to the latest software versions available to them to safeguard against any vulnerabilities and threats.
For additional questions, please contact Keysight.
1 Keysight used commercially reasonable efforts to compile the list of products affected by the IxChariot vulnerability. Keysight offers this information for your convenience and does not warrant it is complete.
Want help or have questions?