CVE-2026-2624 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 2.4% (pctl 83)
Patch early
A public exploit exists.
Description
Missing Authentication for Critical Function vulnerability in ePati Cyber Security Technologies Inc. Antikor Next Generation Firewall (NGFW) allows Authentication Bypass. This issue affects Antikor Next Generation Firewall (NGFW): from v.2.0.1298 before v.2.0.1301.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 2.37% — more likely to be exploited than 83% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2026-02-25 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| epati | antikor next generation firewall |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ePati Antikor NGFW 2.0.1301 - Authentication Bypass | 2026-05-14 |
References
→ the Explorer · watch your stack · NVD