CVE-2025-35062: Newforma Project Center
Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenticated attacker to exploit additional vulnerabilities that require authentication.
Affected products
- Newforma Project Center: before 2023.1 (fixed in 2023.1)
Published 2025-10-09. Last modified 2026-10-08.