Researchers uncovered severe vulnerabilities in Kentico’s Xperience CMS (WT-2025-0006, WT-2025-0007, WT-2025-0011) enabling attackers to achieve remote code execution. These flaws affect version 13 installations using username/password authentication. Attackers can exploit authentication bypasses and a path traversal issue for unauthorized access. Kentico has released patches for these vulnerabilities. Organizations are urged to upgrade immediately.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,