As cited
Copy frozen at (site build).
vulnerabilities
IXON VPN Client
CVE-2026-75925 affects IXON virtual private network (VPN) Client versions before 1.4.7 and allows attackers to achieve remote code execution (RCE) with elevated privileges through improper neutralization of carriage return and line feed (CRLF) sequences. An unauthenticated local attacker can inject malicious configuration directives into a file consumed by a privileged subprocess without visible behavioral changes to the user. IXON released version 1.4.7 as a patch, and as of August 5, 2026, the IXON cloud platform rejects unpatched client connections at the portal and application programming interface (API) to prevent exploit chain completion.
Why it matters: Organizations running IXON VPN Client versions below 1.4.7 face immediate RCE risk with critical CVSS score 9.6; practitioners should prioritize upgrades to v1.4.7 or later across all deployed instances, particularly in critical manufacturing, energy, water, and information technology environments.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
IXON VPN Client
IXON virtual private network (VPN) Client versions before 1.4.7 contain CVE-2026-75925, a CRLF injection vulnerability that allows unauthenticated local attackers to execute commands with elevated privileges through improper neutralization of line-ending sequences in configuration files. The vulnerability affects critical infrastructure sectors worldwide, but IXON cloud rejected connections from unpatched clients as of August 5, 2026, blocking completion of the exploit chain. Version 1.4.7 or later is required to remediate the issue.
Why it matters: Organizations running IXON VPN Client in industrial control systems or critical infrastructure must upgrade to version 1.4.7 or later immediately, as the vulnerability enables root/SYSTEM level code execution on vulnerable endpoints despite the cloud-side connection block.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
IXON VPN Client
IXON virtual private network (VPN) Client versions before 1.4.7 contain CVE-2026-75925, a CRLF injection vulnerability that allows unauthenticated local attackers to execute commands with elevated privileges through improper neutralization of line-ending sequences in configuration files. The vulnerability affects critical infrastructure sectors worldwide, but IXON cloud rejected connections from unpatched clients as of August 5, 2026, blocking completion of the exploit chain. Version 1.4.7 or later is required to remediate the issue.
Why it matters: Organizations running IXON VPN Client in industrial control systems or critical infrastructure must upgrade to version 1.4.7 or later immediately, as the vulnerability enables root/SYSTEM level code execution on vulnerable endpoints despite the cloud-side connection block.
- Source published
- First seen by Cybersecurity Tracker