Critical Flaws Hit Firewalls and Enterprise Servers
Critical vulnerabilities disclosed today include authentication bypasses in firewalls and path traversals in enterprise servers, posing significant risks.

A critical authentication bypass vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows an attacker to bypass authentication. This flaw, tracked as CVE-2026-2624, could expose network defenses to unauthorized access. Organizations using this firewall should prioritize patching or implementing mitigating controls to prevent potential breaches.
Altium Enterprise Server is affected by two critical path traversal vulnerabilities, CVE-2026-11420 and CVE-2026-11414. The first allows an unauthenticated attacker to write arbitrary files to the server's filesystem, while the second involves a hard-coded cryptographic key that enables attackers to forge file download URLs. These flaws could lead to significant system compromise and data manipulation.
Critical vulnerabilities have been disclosed in the Termix SSH platform, including OS command injection and SSH tunnel command interpolation issues. CVE-2026-45744 and CVE-2026-45748, affecting Termix versions prior to 2.3.2, could allow unauthenticated attackers to gain remote code execution or execute arbitrary commands on the server. As Vypr Intelligence reported, these issues pose a severe risk to systems managed by Termix.
Honeywell IQ4x building management controllers, in their factory-default configuration, expose their full web-based HMI without authentication, as detailed in CVE-2026-3611. This allows any unauthenticated user with network access to gain full control of the system. This vulnerability highlights the critical need to reconfigure default security settings on industrial control systems.
IBM Aspera High-Speed Transfer Endpoint and Server are impacted by a critical buffer overflow vulnerability, CVE-2026-8175. Affecting versions 3.7.4 through 4.4.7 Fix Pack 1, this flaw in the asperahttpd process could lead to denial-of-service or potentially remote code execution. IBM's May 2026 patch release addresses this and other issues.
Several critical vulnerabilities have been identified across various products, including SQL injection flaws in Rolantis Information Technologies Agentis (CVE-2025-4285) and Callvision Emergency Code (CVE-2025-0603). Additionally, Netsetman NetMan 204 suffers from unauthenticated administrative access and a hard-coded backdoor account (CVE-2025-71318, CVE-2025-71317). Veeam Backup Viewer has a critical RCE vulnerability as the postgres user (CVE-2026-21708), and Arm Mbed TLS has issues related to serialized SSL context protection and public key export (CVE-2026-34877, CVE-2026-34875).