CVE-2025-26155: Ncp-E Ncp Secure Entry Client

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability.

Affected products

  • Ncp-E Ncp Secure Entry Client: version 13.19 only
  • Ncp-E Secure Enterprise Client: version 13.18 only

Published 2025-11-26. Last modified 2026-06-17.