Quarkslab reported a security issue in the Cato VPN Client tracked as CVE-2026-10739. The report identifies split-tunnel behavior and local privilege escalation as affected security areas, potentially allowing a local attacker to undermine endpoint network-routing controls and obtain elevated permissions.
The issue is notable in the context of Windows privilege-escalation techniques that abuse unsafe file operations, including arbitrary file deletion. Organizations using the Cato VPN Client should identify deployed versions, obtain vendor guidance on affected releases and remediation, and prioritize updates or mitigations on systems where non-administrative users can execute code.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.