CVE-2026-49435: Keysight Hawkeye

Critical severity, CVSS 9.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges.

Affected products

  • Keysight Hawkeye: before 6.0.7 (fixed in 6.0.7)
  • Keysight Ixbypass: before 3.13.0.69 (fixed in 3.13.0.69)
  • Keysight Ixchariot: before 10.0.254 (fixed in 10.0.254)
  • Keysight Ixprobe: before 3.13.0 (fixed in 3.13.0)
  • Keysight Ixtap: before 3.13.0 (fixed in 3.13.0)

Published 2026-08-04. Last modified 2026-08-26.