External risk intelligence

Keysight IxChariot Stack Buffer Overflow Allows Code Execution.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-49435

Keysight IxChariot endpoints are typically deployed as specialized testing and performance monitoring agents within internal enterprise, lab, or network-testing environments. While they communicate over the network, they are rarely intentionally exposed directly to the public internet in standard deployment patterns.

Buffer Overflow

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Keysight IxChariot Endpoint products, allowing unauthenticated remote attackers to execute arbitrary code with administrative privileges by sending a specially crafted network packet. This issue affects systems that utilize this technology for network performance testing and monitoring.

  • Allows unauthorized code execution.
  • Critical flaw warrants attention for affected systems.
  • Confirm relevance and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could send a specially crafted network packet to a vulnerable Keysight IxChariot endpoint. This could lead to arbitrary code execution with administrative privileges.

  • No authentication required.
  • Sending a crafted packet.
  • Arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated remote attacker could potentially execute arbitrary code with administrative privileges on Keysight IxChariot Endpoint systems by sending a specially crafted packet. This could affect the integrity and availability of the affected systems.

  • System data and administrative control.
  • Via specially crafted network packets.
  • Arbitrary code execution with administrative privileges.

Operational Fix

Recommended remediation, mitigation, and detection steps

Keysight IxChariot endpoints are specialized tools, likely managed by network or infrastructure teams. The first step is to confirm their deployment location, assess business criticality and network exposure, and identify the accountable owner to plan remediation.

  • Identify and verify affected systems.
  • Confirm network reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Keysight IxChariot?

Keysight IxChariot is a software suite used by engineers to assess network performance, test throughput, and validate quality of service. It functions by deploying endpoints throughout an infrastructure that simulate traffic and measure delivery metrics across wired, wireless, and cloud networks.

How does CVE-2026-49435 work?

This vulnerability is a stack-based buffer overflow, categorized as CWE-121. It occurs when a program writes more data to a memory buffer than it can hold, overwriting adjacent memory. In this case, the flaw allows an attacker to inject and execute their own code by sending a malformed packet, which can grant them full administrative control over the affected endpoint.

What triggers this buffer overflow?

An unauthenticated remote attacker triggers the issue by sending a specially crafted network packet to the IxChariot endpoint. Standard, legitimate traffic used for performance monitoring and diagnostic testing does not trigger this vulnerability, as the flaw relies on the specific, malicious structure of the packet to exploit the memory handling error.

Is my system at risk according to Halo Surface Signal?

While the vulnerability is critical, Halo Surface Signal notes that IxChariot endpoints are typically deployed as specialized agents within internal labs or controlled network environments. They are rarely intentionally exposed directly to the public internet. However, any endpoint reachable from an untrusted network segment increases the potential risk of unauthorized interaction.

What should I do if I use this software?

First, identify all deployed IxChariot endpoints in your environment and determine who manages them. Once identified, evaluate if these systems are accessible from networks outside your trusted control. Coordinate with your network or infrastructure team to ensure these systems are secured according to vendor guidance and monitor for official updates or configuration changes.

References