Update IXON VPN Client to version 1.4.7 or later on all installed systems. As of August 5, 2026, IXON cloud rejects connections from clients below v1.4.7 at both the portal and back-end API. If the client is no longer needed, uninstall it. Refer to the IXON Trust Center Advisory at https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf for more information.
Quick answers
What is CVE-2026-75925?
Update IXON VPN Client to version 1.4.7 or later on all installed systems. As of August 5, 2026, IXON cloud rejects connections from clients below v1.4.7 at both the portal and back-end API. If the client is no longer needed, uninstall it. Refer to the IXON Trust Center Advisory at https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf for more information.
How severe is CVE-2026-75925?
critical, CVSS 9.6
Is CVE-2026-75925 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-75925 be mitigated?
Update IXON VPN Client to version 1.4.7 or later on all installed systems. As of August 5, 2026, IXON cloud rejects connections from clients below v1.4.7 at both the portal and back-end API. If the client is no longer needed, uninstall it. Refer to the IXON Trust Center Advisory at https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf for more information.
CVSS
9.6
Vendor
IXON
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
IXON VPN Client
Mitigation
Update IXON VPN Client to version 1.4.7 or later on all installed systems. As of August 5, 2026, IXON cloud rejects connections from clients below v1.4.7 at both the portal and back-end API. If the client is no longer needed, uninstall it. Refer to the IXON Trust Center Advisory at https://www.ixon.cloud/Advisories/ADV-2026-08-05.pdf for more information.
CISA and IXON have disclosed a critical CRLF injection vulnerability (CVE-2026-75925) affecting IXON VPN Client versions below 1.4.7. The flaw stems from improper neutralization of CRLF sequences in the local configuration service, allowing an unauthenticated attacker to inject malicious directives into a file later consumed by a privileged subprocess. Exploitation could result in remote code execution with root or SYSTEM-level privileges. The injected configuration persists across client and operating system restarts, and the VPN connection operates normally, making detection difficult. As of August 5, 2026, IXON cloud infrastructure rejects connections from unpatched clients at both the portal and back-end API, blocking the exploit chain for cloud-reliant deployments.