Cato VPN Client: Split-Tunnel and Privilege Escalation (CVE-2026-10739)

·Quarkslab··

Introduction During a Purple Team engagement, we had to list and rank risky components across the network. One of them caught our attention: Cato Client, a VPN client program. It was installed everywhere. It runs privileged services. It talks to a GUI. It handles network configuration. From an attacker perspective, this is exactly the kind of software you want to understand. However, saying "this looks risky" is not enough. There is nothing better than PoC||GTFO. So the question was simple: can ...

Read full article →

Related Articles

Google Chrome silently installs a 4 GB AI model on your device without consent
john-doe · Hacker News · 4mo ago
DNSSEC disruption affecting .de domains – Resolved
warpspin · Hacker News · 4mo ago
Security through obscurity is not bad
mobeigi · Hacker News · 5mo ago
US healthcare marketplaces shared citizenship and race data with ad tech giants
ZeidJ · Hacker News · 5mo ago
The text mode lie: why modern TUIs are a nightmare for accessibility
SpyCoder77 · Hacker News · 5mo ago