CVE-2026-2638: X-VPN macOS Website
High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.
A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a local attacker to leverage a race condition and symlink manipulation to achieve privileged file corruption.
Affected products
- X-VPN X-VPN macOS Website: from 77.0, up to and including 77.5
Published 2026-06-09. Last modified 2026-07-23.