VORANT. Threat Intelligence Sign in Get the full feed

IXON VPN Client flaw enables privileged RCE

routine vulnerability manufacturingenergytechnologyinfrastructure

A CRLF injection bug in IXON VPN Client before 1.4.7 lets local attackers escalate to root/SYSTEM via unauthenticated config injection.

CISA published an ICS advisory for CVE-2026-75925, a CRLF injection vulnerability (CWE-93) in IXON VPN Client versions prior to 1.4.7. The local configuration service accepts unauthenticated changes and writes them to a file consumed by a privileged subprocess without neutralizing line-ending sequences, allowing an attacker to inject additional directives that execute with root or SYSTEM privileges. A contributing weakness (CWE-306, missing authentication) means the configuration interface does not verify the origin of requests. The injected configuration persists across restarts and does not produce any visible behavioral change to the VPN connection, making detection difficult through normal user observation.

IXON has released version 1.4.7 to address the flaw and, as of August 5, 2026, the IXON cloud backend rejects connections from clients running versions below 1.4.7 at both the portal and API level, which breaks the exploit chain since the privileged subprocess and injected listener are only created upon a successful cloud connection. IXON also recommends uninstalling the client entirely if it is no longer needed. This affects deployments across Commercial Facilities, Critical Manufacturing, Energy, Information Technology, and Water and Wastewater sectors worldwide, with the vendor headquartered in the Netherlands.

No known public exploitation has been reported to CISA at this time. CISA's standard ICS mitigations apply: minimize internet exposure of control system devices, isolate ICS networks behind firewalls, and use secure remote access methods. Organizations running affected IXON VPN Client versions should prioritize the update to 1.4.7 or later given the elevated-privilege impact, even absent confirmed in-the-wild exploitation.

Mentioned in this report

Vulnerabilities CVE-2026-75925

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-246-02

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free