IXON VPN Client
A vulnerability in IXON VPN Client versions below 1.4.7 allows an attacker to execute arbitrary code with elevated privileges through malicious web content. The exploit requires user interaction (visiting a malicious site or clicking a link) and creates a privileged subprocess that persists and acts as a listener, giving the attacker full control of the affected computer. As of August 5, 2026, IXON cloud infrastructure rejects connections from unpatched clients, preventing completion of the exploit chain on newly connected clients, but already-compromised or offline systems remain at risk.
- User interaction required: the user must visit a malicious website or click a malicious link
- IXON VPN client running on the computer (versions below 1.4.7)
- Network access to the affected computer via the web browser
/api/v1/advisories/375c7873-03cd-43ac-851b-a06b71a3c921Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.