IXON VPN Client

Plan PatchCVSS 9.6ICS-CERT ICSA-26-246-02Aug 5, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

A vulnerability in IXON VPN Client versions below 1.4.7 allows an attacker to execute arbitrary code with elevated privileges through malicious web content. The exploit requires user interaction (visiting a malicious site or clicking a link) and creates a privileged subprocess that persists and acts as a listener, giving the attacker full control of the affected computer. As of August 5, 2026, IXON cloud infrastructure rejects connections from unpatched clients, preventing completion of the exploit chain on newly connected clients, but already-compromised or offline systems remain at risk.

What this means
What could happen
An attacker could run arbitrary commands on the computer running the IXON VPN client with elevated system privileges, potentially compromising engineering workstations, SCADA front-ends, or any computer used to access industrial equipment remotely.
Who's at risk
Any organization using IXON VPN client on engineering workstations, SCADA front-ends, or remote access computers for industrial control systems, particularly water utilities and power systems that rely on remote connectivity to PLCs, gateways, or cloud-based asset management platforms.
How it could be exploited
An attacker tricks a user into visiting a malicious website or clicking a link while the IXON VPN client is running. The malicious content exploits the client vulnerability to inject code that executes with elevated privileges. The injected code persists as a privileged listener, allowing the attacker to run commands or access remote systems through the VPN tunnel.
Prerequisites
  • User interaction required: the user must visit a malicious website or click a malicious link
  • IXON VPN client running on the computer (versions below 1.4.7)
  • Network access to the affected computer via the web browser
remotely exploitablelow complexityuser interaction requiredelevated privilegesaffects engineering/admin workstations
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (1)
ProductAffected VersionsFix Status
VPN Client<1.4.7No fix yet
Remediation & Mitigation
0/3
Do now
0/3
HOTFIXUpdate IXON VPN client to version 1.4.7 or later on all computers where it is installed
WORKAROUNDUninstall IXON VPN client from computers where it is no longer needed
HARDENINGRestrict user web browsing to trusted sites on computers running IXON VPN client until patching is complete
API: /api/v1/advisories/375c7873-03cd-43ac-851b-a06b71a3c921

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

IXON VPN Client | CVSS 9.6 - OTPulse