← back
CVE-2026-2624

Authentication Bypass in ePati's Antikor NGFW

CVSS 9.8 CRITICALEPSS 2.2%CWE-306
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 9.8EPSS 2.2%KEV nãoPoC públicaNuclei Metasploit Patch
Lifecycle
25 Feb 2026Published on NVD
14 May 2026Public PoC
Recommendation: Plan a near-term fix — a public PoC already exists.
Missing Authentication for Critical Function vulnerability in ePati Cyber ​​Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass. This issue affects Antikor Next Generation Firewall (NGFW): from v.2.0.1298 before v.2.0.1301.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →