CVE-2025-27377: Altium Designer

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensitive design data.

Affected products

  • Altium Designer: from 24.9.0, before 25.2.0 (fixed in 25.2.0)

Published 2026-01-22. Last modified 2026-06-17.