Skip to main content
LiMP VPN
All news

ViPNet Client: Critical CVSS 9.0 Flaw Exploited in Russia

ViPNet Client: Critical CVSS 9.0 Flaw Exploited in Russia

In short: Positive Technologies added the ViPNet Client flaw (PT-2026-19, CVSS 9.0) to its August 2026 trending-threats digest. Attackers exploited it to plant the ShadowRelay backdoor in at least eight Russian organizations by pushing fake software updates through the platform's built-in MFTP protocol. Patch immediately or disable the update service as a stopgap.

What Happened

Between June 1 and July 14, 2026, threat actors carried out targeted attacks against organizations running ViPNet Client 4 and ViPNet Administrator 4.6.11 — a Russian secure-communications platform by InfoTeCS deployed on more than 10 million workstations nationwide. The campaign was uncovered by Positive Technologies Expert Security Center (PT ESC); Russia's National Computer Incident Response Center (НКЦКИ) issued its own advisory to Russian organizations.

The vulnerability is tracked as PT-2026-19 (BDU:2026-09885, CVSS 9.0 — Critical). In August 2026 Positive Technologies listed it among actively exploited trending vulnerabilities.

How the Attack Worked

ViPNet's built-in MFTP protocol handles secure file exchange between network nodes — exactly the kind of trusted internal channel attackers want to abuse. After first gaining control of a ViPNet Administrator node, the attackers used MFTP to distribute a crafted .ctl envelope file masquerading as a legitimate software update. Two techniques were chained:

  • Path Traversal — a path-handling flaw allowed the attacker to write a file outside the permitted update directory;
  • DLL Hijacking — a malicious replacement for wtsapi32.dll was loaded with elevated privileges during the normal client update routine.

The infection chain then proceeded: the malicious code injected itself into the svchost.exe system process, established a proxy for command-and-control communications, and deployed the ShadowRelay backdoor together with the Donnect downloader. Because the attack required prior control of an Administrator node, this was a targeted campaign rather than opportunistic mass exploitation.

Scale: Who Was Affected

PT ESC confirmed successful exploitation in at least eight Russian organizations. Names were withheld. ViPNet is widely deployed across government agencies, financial institutions, industrial enterprises, and operators of critical information infrastructure — making these high-value targets for sophisticated actors.

Russia's Kontur Certification Authority officially urged all ViPNet Client users to apply the available patches. InfoTeCS had already released fixes before PT published its August digest — organizations need to confirm they are running updated builds. For broader guidance on layered data protection, visit our security blog.

How to Protect Yourself

InfoTeCS released the following patched builds:

  • ViPNet Client 4 — build 4.5.3-65211 or 4.5.5.24749;
  • ViPNet Administrator 4 — build 4.6.11.5114.

If immediate patching is not feasible: stop the "ViPNet system update" service and disable its autostart. This closes the primary attack vector as an interim measure.

The ViPNet incident is a clear reminder that purpose-built security software becomes an attack vector when left unpatched. Data protection is a multi-layer challenge: software updates close vulnerabilities in applications, while network-level traffic encryption — such as LiMP VPN — protects data in transit, independently of the state of endpoint software.

Sources

ViPNet Client: Critical CVSS 9.0 Flaw Exploited in Russia