A critical vulnerability (CVE-2026-75925) has been identified in IXON VPN Client versions prior to 1.4.7, involving Improper Neutralization of CRLF Sequences (CWE-93). Successful exploitation allows an attacker to perform remote code execution with elevated privileges (root or SYSTEM) on the affected machine. The vulnerability stems from configuration values being written to a file consumed by a privileged subprocess without sanitizing line-ending sequences, and the configuration interface accepts changes without authentication (CWE-306). The injected configuration persists across restarts, making it stealthy as no behavioral changes are visible to users. CVSS v3.1 score is 9.6 (CRITICAL) and CVSS v4.0 score is 9.4 (CRITICAL). Affected sectors include Commercial Facilities, Critical Manufacturing, Energy, IT, and Water/Wastewater globally. IXON has mitigated the issue server-side by rejecting connections from clients below v1.4.7 as of August 5, 2026, and recommends updating to v1.4.7 or later. No known public exploitation has been reported to CISA at this time.