CVE-2025-27377: Altium Designer
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Altium Designer version 24.9.0 does not validate self-signed server certificates for cloud connections. An attacker capable of performing a man-in-the-middle (MITM) attack could exploit this issue to intercept or manipulate network traffic, potentially exposing authentication credentials or sensitive design data.
Affected products
- Altium Designer: from 24.9.0, before 25.2.0 (fixed in 25.2.0)
Published 2026-01-22. Last modified 2026-06-17.