Critical CRLF Injection Vulnerability in IXON VPN Client (CVE-2026-75925)
Versions prior to 1.4.7 allow unauthenticated remote code execution with root or SYSTEM privileges; cloud-side mitigation now blocks exploit chains.
Key Takeaways
- CVE-2026-75925 is a critical CRLF injection vulnerability in IXON VPN Client affecting versions before 1.4.7.
- Unauthenticated attackers can achieve remote code execution with root or SYSTEM privileges by injecting malicious directives into configuration files.
- The injected configuration persists across restarts and the VPN connection operates normally, making exploitation difficult to detect.
- CVSS v3 base score is 9.6 (CRITICAL).
- As of August 5, 2026, IXON cloud rejects connections from unpatched clients, blocking the exploit chain for cloud-reliant deployments.
Related Security News

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
The maintainers of the official MCP Python SDK disclosed a security vulnerability that could allow a malicious server to trick applications into divulging OAuth credentials. The issue affects the handling of client secrets, authorization codes, and PKCE proof keys when communicating with token endpoints.

Star Blizzard Campaign Targets 100+ Organizations with Fake Event Invitations
Microsoft reports that the Russian state-sponsored threat actor Star Blizzard has been conducting a sustained campaign since January 2026, using fake event invitations to trick targets into installing a backdoor on Windows computers. The operation has affected more than 100 organizations, primarily in the U.S. and U.K., with victims tied to Ukraine. At least one infection has been confirmed, though the full extent of breaches and data exfiltration remains unverified.

