CVE-2025-10220: Axxonsoft Axxon One

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0.0 through 2.0.4 on Windows allows a remote attacker to execute arbitrary code or bypass security features via exploitation of vulnerable third-party packages such as Google.Protobuf, DynamicData, System.Runtime.CompilerServices.Unsafe, and others.

Affected products

  • Axxonsoft Axxon One: from 2.0.0, up to and including 2.0.4

Published 2025-09-10. Last modified 2026-09-26.