VHC 10-K & 10-Q changes, risk factors and insider trading
VirnetX Holding Corp · Nasdaq · Patent Owners & Lessors · CIK 1082324 · All filings on SEC.gov
At a glance
What changed in the latest 10-K
Risk Factors
New heading “We plan to offer our products to government entities, which are subject to a number of challenges and risks.”
New heading “Our business could be adversely affected if our employees cannot obtain and maintain required personnel security clearances or we cannot establish and maintain a required facility security clearance.”
New heading “Changes in tax law could materially impact our business, results of operations and financial condition.”
Removed heading “Our business has been, and may continue to be, negatively affected by activist shareholders.”
Removed heading “Failure to meet the NYSE’s continued listing requirements could result in the suspension of trading of our common stock and a subsequent delisting of our common stock.”
Largest changes
“Failure to meet the NYSE’s continued listing requirements could result in the suspension of trading of our common stock and a subsequent delisting of our common stock.”see in full comparison
“If shares of our common stock are delisted from the NYSE, there may be no public market for our common stock. Any over-the-counter or other market that does develop would likely be characterized by decreased liquidity and greater volatility, which may materially and adversely affect the value of our common stock. …”see in full comparison
“The U.S. Department of Justice has also issued regulations regarding certain bulk sensitive personal data transfers. We cannot yet fully determine the impact these or future laws, regulations and standards may have on our business, but they may require us to modify our data processing practices and policies and to incur substantial costs and expenses in efforts to comply. …”see in full comparison
“Our common stock could also be delisted if our average global market capitalization over a consecutive 30 trading-day period is less than $15 million. Our average global market capitalization over a consecutive 30 trading-day period may fall below $15 million based on continued volatility and fluctuations in the market price of our common stock. …”see in full comparison
“Our business could be adversely affected if our employees cannot obtain and maintain required personnel security clearances or we cannot establish and maintain a required facility security clearance.”see in full comparison
“We plan to offer our products to government entities, which are subject to a number of challenges and risks.”see in full comparison
Full comparison: every changed paragraph (43)
Our operating results may not be consistent and may be difficult to predictpredict, and we may not be able to achieve or sustain profitability in the future.
We had a net loss of $6.2$18.2 million for the quarteryear ended December 31, 2024.2025 We hadand a net loss of $18.2 million for the year ended December 31, 2024. As of December 31, 2024,2025, we had an
accumulated deficit
of $204.7$222.9 million. Our operating results have fluctuated in the past due to several factors and may fluctuate in the future due to the same or similar factors, which include but are not limited to the following:
Our operating results have fluctuated in the past due to several factors and may fluctuate in the future due to the same or similar factors, which include but are not limited to the following:
These fluctuations may make our business particularly difficult to manage, adversely affect our business and operating results, make our operating results difficult for investors to predict and,
and, further, cause our results to fall below investor’s expectations and adversely affect the market price of our common stock. If we fail to increase our revenue to offset any increases in our operating expenses,revenue, we may not achieve or sustain
profitability in the future.
Part of ourOur business strategy is to enter into partnerships, strategic investments, and other cooperative arrangements with other companies and government agencies.
We have invested in and we
continue to seek to invest in or acquire businesses, technologies, or other assets that we believe could complement or expand our business. In addition, we are regularly involved in cooperative efforts with respect to the
incorporation of our
products into products of others and vice versa, collaborative research and development efforts with government and university laboratories, distributor and reseller arrangements and service provider partnerships. These
relationships are
generally non-exclusive, and some of our partners also have cooperative relationships with certain of our competitors or offer some products and services that are competitive with ours. If we lose third-party relationships, if these
relationships are not commercially successful, or if we are unable to enter into third-party relationships on commercially reasonable terms in the future, our business could be negatively impacted.
The sales cycle between initial customer contact and the execution of a contract or license agreement with a customer or purchaser of our products can vary widely. We expect that our sales cycles will be long and unpredictable due to several factors, including but not limited to:
We plan to offer our products to government entities, which are subject to a number of challenges and risks.
Government entities have announced reductions in, or experienced increased pressure to reduce, government spending. Continued U.S. debt, income tax and budget issues, government shutdowns and delays in approving U.S. spending or reductions in such may adversely impact existing or future U.S. public sector transactions and affect future sales of our products and services to such entities. Additionally, any future government demand and payment for our products may be more volatile as they are affected by public sector budgetary cycles, funding authorizations, and the potential for funding reductions or delays, making the time to close such transactions more difficult to predict.
In addition, sales to government entities are subject to a number of risks. Government entities may continue use of legacy products and services indefinitely and be slow to transition to more modern products and services, including ours, or impose challenging regulatory requirements on such adoptions, any of which may inhibit the growth of our public sector business. Selling to government entities can be highly competitive, expensive and time consuming, often requiring significant upfront time and expense without any assurance that we will successfully sell our products to such governmental entity. Government entities may require contract terms that differ from our standard arrangements or require the maintenance of certain facility and employee security clearance, which may be difficult to obtain or maintain.
Our business could be adversely affected if our employees cannot obtain and maintain required personnel security clearances or we cannot establish and maintain a required facility security clearance.
Certain government contracts may require our employees to maintain various levels of security clearances and may require us to maintain a facility security clearance to comply with U.S. and international government agency requirements. Many governments have strict security clearance requirements for personnel who perform work in support of classified programs. Obtaining and maintaining security clearances for employees typically involves a lengthy process, and it can be difficult to identify, recruit, and retain employees who already hold security clearances. If our employees are unable to obtain security clearances in a timely manner, or at all, or if our employees who hold security clearances are unable to maintain their clearances or terminate employment with us, then we may be unable to bid on or win new classified contracts. To the extent we are not able to obtain or maintain a facility security clearance, we may not be able to bid on or win classified contracts, which would have an adverse impact on our business, financial condition, and results of operations.
We have limited technical resources and are at an early stage in commercialization of our VirnetX One™ platform and software products.products, as well as our DE, DTE
methods, MBSE, and cyber threat assessment services.
The market for ZTNA security solutions is rapidly evolving and highly competitive as new entrants and traditional network solutions companies offer cloud-based cybersecurity solutions. Competition in our business is highly diverse, and while our competitors offer different products and services, there is often competition for contracts that are part of government budgets. We also may face competition from companies that provide products and services to the U.S. Government, including defense contractors.
TheMany market for ZTNA security solutions is rapidly evolving and highly competitive as new entrants and traditional network solutions companies offer cloud-based cybersecurity solutions. Many
of our competitors and potential competitors have established brand recognition, larger customer bases, and greater resources than we do. Our primary competitors in the ZTNA market include
Appgate, Cloudflare, and Illumio. In the enterprise
market, our primary competitors include Zscaler (ZPA), Palo Alto Networks (Prisma Access), Cisco (Umbrella), Citrix (Secure Private Access), Netskope (Private Access for ZTNA) and Cato Networks. As
we expand our product offerings and use cases,
we will begin to compete with companies that offer bundled security-as-a-service solutions that include Secure Access Service Edge (SASE) and Security Service Edge (SSE). With the introduction of new
technologies and market entrants, we expect
competition to intensify in the future. For example, disruptive technologies such as generative AI has and may continue to fundamentally alter the market for our services in unpredictable ways and reduce
customer demand. If we fail to compete
effectively, our business will be harmed. Some of our competitors offer their products or services at lower prices or for free as part of a broader bundled product sale or enterprise license arrangement, which
has placed pricing pressure on our
business. If we are unable to achieve our target pricing levels, our operating results will be negatively impacted. For us to compete effectively, we need to introduce new products and services in a timely and
cost-effective manner, meet
customer expectations and needs at prices that customers are willing to pay, and continue to enhance the features and functionalities of our cloud content management platform. In addition, pricing pressures and increased
competition could
result in reduced sales, lower margins, losseslosses, or the failure of our services to achieve or maintain widespread market acceptance, any of which could harm our business.
Many of our competitors are able to devote greater resources to the development, promotion and sale of their products or services. In addition, many of our competitors have established marketing
marketing relationships and major distribution agreements with government agencies, channel partners, consultants, system integratorsintegrators, and resellers. Competitors may offer products or services at lower prices or with greater depth than our
services. Our
competitors may be able to respond more quickly and effectively to new or changing opportunities, technologies, standardsstandards, or customer requirements. Furthermore, some potential customers, particularly large enterprises, may elect
to develop their own
internal solutions. In addition, the U.S. government and foreign governments may develop, construct, launch and operate their own ZTNA security solutions with capabilities comparable or similar to ours, which could reduce their need to rely on us and
other commercial suppliers. For any of these reasons, we may not be able to compete successfully against our competitors.
Our products are highly technical and complex and, when deployed, may contain errors or defects. Despite testing, some errors in our products may only be
discovered after a product has been
installed and used by customers. Any errors or defects discovered in our products after commercial release could result in failure to achieve market acceptance, loss of revenue or delay in revenue recognition, loss
of customers and increased
service and warranty cost, any of which could adversely affect our business, operating results, and financial condition. In addition, we could face claims for product liability, tort, or breach of warranty, including claims
relating to changes
to our products made by our channel partners. The performance of our products could have unforeseen or unknown adverse effects on the networks over which they are delivered as well as on third-party applications and services that
utilize our
services, which could result in legal claims against us,us harming our business. Furthermore, we expect to provide implementation, consulting, and other technical services in connection with the implementation and ongoing maintenance of our
products, which typically involves working with sophisticated software, computing, and communications systems. We expect that our contracts with customers will contain provisions relating to warranty disclaimers and liability limitations, which may
may not be upheld. Defending a lawsuit, regardless of its merit, is costly and may divert management’s attention and adversely affect the market’s perception of us and our products. In addition, if our business liability insurance coverage proves
proves inadequate or future coverage is unavailable on acceptable terms or at all, our business, operating results, and financial condition could be adversely impacted.
Our business will depend upon, among other things, the capacity, reliability, security, and unimpeded access of the infrastructure owned by third parties that we will use to deploy our offerings.
offerings. We have no control over the operation, quality, or maintenance of a significant portion of that infrastructure or whether those third parties will upgrade or improve their equipment. We depend on these companies to maintain the
operational integrity
of our connections. If one or more of these companies is unable or unwilling to supply or expand their levels of service to us in the future, our operations could be severely interrupted. Also, to the extent that the
number of users of networks utilizing our current or future products suddenly increases, the technology platform and secure hosting services which will be required to accommodate a higher volume of traffic may result in slower response times or
service interruptions. System interruptions or increases in response time could result in a loss of potential or existing users and, if sustained or repeated, could reduce the appeal of the networks to users. In addition, users depend on
real-time communications; outages caused by increased traffic could result in delays and system failures. These types of occurrences could cause users to perceive that our solution does not function properly and could therefore adversely affect
our ability to attract and retain licensees, strategic partners, and customers.
We face security threats from malicious third parties that could obtain unauthorized access to our systems, network, and data. We expect to retain certain confidential and proprietary customer information in our secure
data centers and secure domain name registry, as well as personal data and other confidential and proprietary information relating to our business. It
will be critical to our business strategy that our facilities and infrastructure, including our
secure domain name servers, remain secure and are perceived by the marketplace to be secure. Our secure domain name registry operations will also
depend on our ability to maintain our computer and telecommunications equipment in effective working
order and to reasonably protect our systems against interruption, and potentially depend on protection by other registrars in the shared
registration system..system. Additionally, we maintain confidential and proprietary business information, including trade
secrets. We expect to continue to have to expend significant time and money to maintain or increase the security of our products, facilities,
and infrastructure. Security technologies are constantly being tested by computer professionals, academics
and “hackers.” Advances in computer capabilities and the techniques for attacking security solutions, new discoveries in the field of
cryptography or other events or developments could result in compromises or breaches of our security measures and
could make some or all our products obsolete or unmarketable. Likewise, we may need to dedicate engineering and other resources to
mitigate or eliminate security vulnerabilities and may find it necessary or appropriate to repair or replace products
already sold or licensed to our customers. Despite the security measures that we and our service providers utilize, our
infrastructure and that of our service providers may be vulnerable to physical break-ins, ransomware, computer viruses, other
malicious code attacks by hackers, phishing attacks, social engineering, or similar disruptive problems. There can be
no assurances our security measures or those of our service providers will prevent security breaches or incidents. Any disruption or
security breach or incident that we or our service providers suffer or are perceived to suffer, including any
such disruption, breach or incident resulting in a loss of, or damage to, data or systems, or inappropriate disclosure, access, loss, or
other processing of confidential, financial, proprietary or personal information, including data related to
our personnel, could result in loss, disclosure or other unauthorized processing of such data, could delay our research and development or
commercialization efforts, could compel us to comply with breach notification laws and regulations,
subject us to mandatory corrective action, and otherwise subject us to liability under laws and regulations that protect the privacy and security of
personal information. It is possible that we may have to expend additional financial and other
resources to address such problems. Remote work by our personnel and those of third parties has resulted in increased vulnerability to cyber-attacks. Additionally, geopolitical tensions and conflicts may create increased risks of cyber-attacks.
As a provider of Internet security software and technology, we may be the target of dedicated efforts by hackers and other third parties to overcome or defeat our security measures. Any physical or electronic break-in or other security breach
or incident or compromise impacting our products, or any information stored at our secure data centers and domain name registration systems, including any compromise due to human error or employee or contractor malfeasance, may jeopardize the
security of information stored on our premises or in the computer systems and networks of our customers. Additionally, any such data security incident, or the perception that one has occurred could also result in adverse publicity, harm to our
reputation and competitive position, and therefore adversely affect the market’s perception of the security of electronic commerce and communications over IP networks as well as the security or reliability of our services, which could have a
material adverse impact on our business, financial condition, and results of operations.
Additionally, during times of war and other geopolitical tensions and conflicts may create increased risks of cyber-attacks. As a provider of Internet security software and technology, we may be the target of dedicated efforts by hackers and other third parties to overcome or defeat our security measures. Any physical or electronic break-in or other security breach or incident or compromise impacting our products, or any information stored at our secure data centers and domain name registration systems, including any compromise due to human error or employee or contractor malfeasance, may jeopardize the security of information stored on our premises or in the computer systems and networks of our customers. Additionally, any such data security incident, or the perception that one has occurred could also result in adverse publicity, harm to our reputation and competitive position, and therefore adversely affect the market’s perception of the security of electronic commerce and communications over IP networks as well as the security or reliability of our services, which could have a material adverse impact on our business, financial condition, and results of operations.
A security breach or other security incident, or the perception any such event has occurred, could require a substantial level of financial resources to address and otherwise respond to, may be
be difficult to identify or address in a timely manner, and could result in claims, investigations, inquiries, and other proceedings or actions by private parties or governmental entities that may divert management’s attention and require the
expenditure of significant time and resources, and which may cause us to incur substantial fines, penalties, or other liability and related legal and other costs. Cybersecurity risks pose a particularly significant risk to our business given our
our focus on providing internet security software and secure communications technology. Any actual or perceived security breach or other security incident may also harm our reputation, result in a loss of customers, and make it more difficult or
or impossible for us to successfully market to others. Any of the foregoing matters could harm our business, operating resultsresults, and financial condition.
Privacy and data security concerns, data collectioncollection, and transfer restrictions and related domestic or foreign regulations may limit the use and adoption of
of our solutions and adversely affect our business.
Further, many foreign countries and governmental bodies, including the European Union (“EU”), where we conduct business, have laws and regulations concerning
the collection and use of
personal data obtained from their residents or by businesses operating within their jurisdiction. These laws and regulations often are more restrictive than those in the United States. Laws and regulations in these
jurisdictions apply broadly
to the collection, use, storage, disclosure, and security of data that identifies or may be used to identify or locate an individual.
We also expect that there will continue to be new proposed laws, regulations and industry standards concerning privacy, data protection and information security in the United States, the EU, and
and other jurisdictions. For example, the European Commission maintains a General Data Protection Regulation (the “GDPR”) that imposes stringent data protection requirements and provides for substantial penalties for noncompliance. The United
Kingdom has
enacted a Data Protection Act and legislation referred to as the UK GDPR that substantially implements the GDPR and provides for a penalty regime similar to the GDPR. The United Kingdom made targeted amendments to the Data Protection Act and the UK
GDPR in the UK Data (Use and Access) Act, effective June 19, 2025. We may be required to incur substantial expense in order to make
significant changes to our products and operations to address compliance with the GDPR and similar legislation, such
as the UK GDPR and UK Data Protection Act, all of which may adversely affect our revenue and product sales. California has
enacted legislation, the California Consumer Privacy Act (the “CCPA”) that, among other things, requires covered companies to provide
disclosures to California consumers, and afford such consumers abilities to opt-out of certain sales of
personal information. The CCPA was modified and expanded by the California Privacy Rights Act (the “CPRA”), which was approved by California voters in
the November 2020 election. Additionally, other U.S. states continue to propose, and in
certain cases adopt, privacy-focused legislation. For example, Connecticut, Virginia, UtahUtah, and Colorado enacted legislation similar to the CCPA and CPRA that
took effect in 2023; Florida, Montana, Oregon, and Texas have enacted similar
legislation that has becamebecome effective in 2024; Delaware, Nebraska, Maryland, New Hampshire, New Jersey, Minnesota, Tennessee, and Iowa have enacted similar legislation that has or will become effective in 2025;legislation, and
Indiana, Kentucky, and Rhode
Island have enacted similar legislation that willhas become effective in 2026. We cannot yet fully determine the impact these or future laws, regulations and standards may have on our business, but they may require us to modify our data processing
practices and policies and to incur substantial costs and expenses in efforts to comply. Privacy, data protection and information security laws and regulations are often subject to differing interpretations, may be inconsistent among
jurisdictions, and may be alleged to be inconsistent with our current or future practices. Additionally, we may be bound by contractual requirements applicable to our collection, use, processing, and disclosure of various types of data,
including personal data, and may be bound by, or voluntarily comply with, self-regulatory or other industry standards relating to these matters. These and other requirements could reduce demand for our products, increase our costs, impair our
ability to grow our business, or restrict our ability to store and process data or, in some cases, impact our ability to offer our service in some locations and may subject us to liability. Any failure or perceived failure to comply with
applicable laws, regulations, industry standards, and contractual obligations may adversely affect our business. Further, in view of new or modified federal, state, or foreign laws and regulations, industry standards, contractual obligations
and other legal obligations, or any changes in their interpretation, we may find it necessary or desirable to fundamentally change our business activities and practices or to expend significant resources to modify our product and otherwise
adapt to these changes. We may be unable to make such changes and modifications in a commercially reasonable manner or at all, and our ability to develop new products and features could be limited.
The U.S. Department of Justice has also issued regulations regarding certain bulk sensitive personal data transfers. We cannot yet fully determine the impact these or future laws, regulations and standards may have on our business, but they may require us to modify our data processing practices and policies and to incur substantial costs and expenses in efforts to comply. Privacy, data protection and information security laws and regulations are often subject to differing interpretations, may be inconsistent among jurisdictions, and may be alleged to be inconsistent with our current or future practices. Additionally, we may be bound by contractual requirements applicable to our collection, use, processing, and disclosure of various types of data, including personal data, and may be bound by, or voluntarily comply with, self-regulatory or other industry standards relating to these matters. These and other requirements could reduce demand for our products, increase our costs, impair our ability to grow our business, or restrict our ability to store and process data or, in some cases, impact our ability to offer our service in some locations and may subject us to liability. Any failure or perceived failure to comply with applicable laws, regulations, industry standards, and contractual obligations may adversely affect our business. Further, in view of new or modified federal, state, or foreign laws and regulations, industry standards, contractual obligations and other legal obligations, or any changes in their interpretation, we may find it necessary or desirable to fundamentally change our business activities and practices or to expend significant resources to modify our product and otherwise adapt to these changes. We may be unable to make such changes and modifications in a commercially reasonable manner or at all, and our ability to develop new products and features could be limited.
Our business has been, and may continue to be, negatively affected by activist shareholders.
Responding to actions and communications by activist shareholders is costly and time-consuming, has diverted the attention of management, our Board of Directors and our employees, and may be
disruptive to our operations. Additionally, perceived uncertainties as to our future direction as a result of shareholder activism may lead to the perception of a change in the direction of our business or other instability, which may be
exploited by our competitors, cause concern to our current or potential customers, and make it more difficult to attract and retain qualified personnel. Furthermore, if customers choose to delay, defer or reduce transactions with us or do
business with our competitors instead of us, then our business, financial condition and operating results would be adversely affected. In addition, our share price could experience periods of increased volatility as a result of shareholder
activism.
The exercise of our outstanding stock options and warrants, and the issuance of RSUs and restricted stock would result in a dilution of our current
stockholders’ voting
power and an increase in the number of shares eligible for future resale in the public market which may negatively impact the market price of our stock.
The exercise of our outstanding vested stock options and warrants, and the vesting of RSUs and restricted stock dilutes the ownership interests of our existing stockholders. As of December
31, 2024,2025, we had
727,884 outstanding options, warrantsoptions and RSUs to purchase an aggregate of 265,040 shares of common stock representing approximately 6.25%18% of our total shares outstanding of which 242,352234,842 were vested. To the extent restricted stock is awarded, outstanding stock
options or warrants are exercised
exercised, and RSUs vest, additional shares of common stock will be issued, existing stockholders’ percentage voting interests will declinedecline. andAlso, the number of shares eligible for resale in the public market will increase.
Suchincrease and such increase may have a negative effect on the value or market trading
price of our common stock.
As of December 31, 2024,2025, our executive officers and directors beneficially owned approximately 18%16% of our outstanding common stock. Because of their beneficial ownership interest, our
officers and
directors could significantly influence stockholder actions of which you disapprove or that are contrary to your interests.actions. This ability to exercise significant influence could prevent or significantly delay another company from
acquiring or merging with us.
We have protective provisions in our amended and restated certificate of incorporation (“Restated Charter”) and amended and restated bylaws (“Restated Bylaws”) that could delay, discourage, or prevent
a third party from acquiring control of us
without the approval of our Board of Directors. These protective provisions include:
In addition, the provisions of Section 203 of the Delaware General Corporation Law govern us. These provisions may prohibit large stockholders, particularly those owning 15% or more of our
outstanding voting stock, from merging or combining with us for a certain period of time.
In addition, the provisions of Section 203 of the Delaware General Corporation Law govern us. These provisions may prohibit large stockholders, particularly those owning 15% or more of our outstanding voting stock, from merging or combining with us for a certain period of time. These and other provisions in our Restated Charter, our Restated Bylaws and under Delaware law could discourage potential takeover attempts, reduce the price that investors might be willing to pay for shares of our common stock in the future and result in the market price being lower than it would be without these provisions.
Failure to meet the NYSE’s continued listing requirements could result in the suspension of trading of our common stock and a subsequent delisting of
our common stock.
On August 28, 2024, we received a written notification from the NYSE that as of August 27, 2024, we were not in compliance with the continued listing standards set forth in Section 802.01B of
the NYSE Listed Company Manual because the average global market capitalization over a consecutive 30 trading-day period and stockholders’ equity were both less than $50 million. In accordance with applicable NYSE procedures, we submitted a
plan to the NYSE on October 11, 2024, and provide quarterly updates advising it of the definitive actions we have taken, are taking and plan to take that would bring us into conformity with the standard set forth in Section 801.01B within 18
months of receipt of the written notification. The written notification has no immediate impact on our ongoing business operations, reporting requirements with the SEC or the listing of our common stock on the NYSE at this time, subject to the
Company’s continued compliance with the plan and NYSE’s other continued listing standards. We are considering all available options to regain compliance with NYSE’s continued listing standards but can provide no assurances that we will be able
to satisfy the requirements of the NYSE.
Our common stock could also be delisted if our average global market capitalization over a consecutive 30 trading-day period is less than $15 million. Our average global market capitalization
over a consecutive 30 trading-day period may fall below $15 million based on continued volatility and fluctuations in the market price of our common stock. In the event that our stock price does not meet the global market capitalization
requirement, the NYSE will promptly suspend our common stock from trading on the NYSE and will simultaneously begin the process to delist our common stock, subject to our right to appeal under NYSE rules. While we may appeal this decision,
there is no assurance that any appeal we undertake will be successful.
If shares of our common stock are delisted from the NYSE, there may be no public market for our common stock. Any over-the-counter or other market that does develop would likely be
characterized by decreased liquidity and greater volatility, which may materially and adversely affect the value of our common stock. A delisting of our common stock could negatively impact the Company and holders of our common stock, including
by reducing the willingness of investors to hold our common stock because of the resulting decreased price, liquidity and trading of our common stock, limited availability of price quotations, and reduced news and analyst coverage. These
developments may also require brokers trading in our common stock to adhere to more stringent rules and may limit our ability to raise capital by issuing additional shares of common stock in the future. Delisting may adversely impact the
perception of our financial condition, cause reputational harm with investors, our employees and parties conducting business with us, and limit our access to debt and equity financing. The perceived decrease in value of employee equity
incentive awards may reduce their effectiveness in encouraging performance and retention.
Our business may be adversely affected by instability, disruption, or destruction in a geographic region in which we operate, regardless of cause, including war, terrorism, riot, civil
insurrection, or social unrest, and natural or manmade disasters, including famine, flood, fire, earthquake, storm, or pandemic events and spread of disease. Our business may also be adversely affected by further downturn in macroeconomic conditions,
conditions, including inflation and rising interest rates, tariffs, trade wars, global political and economic uncertainty and tensions, such as the ongoing Russia-Ukraine and Israel-HamasMiddle Easts conflicts, as well as any related political or economic
response, counter
responses or otherwise, financial services sector instability, a reduction in business confidence and activity, financial market volatility, unexpected changes in tax law or policy, and other factors. Such events can adversely
affect our operations
or the economy as a whole and may cause our customers to delay their decisions on spending for the services we provide and perpetuate significant changes in regional and global economic conditions and cycles. These events
may also pose risks to our
personnel and to physical facilities and operations, which could adversely affect our financial results.
Changes in tax law could materially impact our business, results of operations and financial condition.
Changes to U.S. federal, state, and local, and foreign tax laws that may be enacted in the future could impact the tax treatment of our business operations. Our effective tax rate could be adversely affected by several factors, many of which are outside of our control, including changes in the mix of earnings and losses in countries with differing statutory tax rates, changes in the valuation of deferred tax assets and liabilities, changes in tax laws, rates, treaties and regulations or the interpretation of the same, changes to the financial accounting rules for income taxes, the outcome of current and future tax audits, examinations or administrative appeals and certain non-deductible expenses. In addition, many jurisdictions, including the United States, are actively considering changes to existing tax laws or have proposed or enacted new laws, such as the recently enacted U.S. federal tax legislation commonly referred to as the One Big Beautiful Bill Act (OBBB Act), that could increase our tax obligations in countries where we do business or cause us to change the way we operate our business. We are currently evaluating the full impact of the OBBB Act on us. As of December 31, 2025, the OBBB Act has had no material income tax impact on our financial statements.
In addition, the Organization for Economic Cooperation and Development has proposed imposing a 15% global minimum tax under the Pillar Two Model Rules (Pillar Two), and this proposal has been adopted or is being considered by a number of countries, which could impact our business if we expand internationally. However, on June 28, 2025, the G7 released a joint statement that it had reached an understanding with the United States for a side-by-side system based on certain accepted principles, including that U.S.-parented groups, such as ours, would be exempt from certain provisions of Pillar Two. Any of these developments or changes in U.S. federal, state or international tax laws or tax rulings could adversely affect our effective tax rate and our operating results. As of December 31, 2025, we are not yet subject to Pillar Two due to the level of gross receipts.
Our common stock is currently listed on the NYSENasdaq Stock Market LLC (Nasdaq) and was previously listed on theNYSE and NYSE American LLC (formerly the NYSE MKT LLC). Over the past years,year, the market
price of our common stock has experienced significant fluctuations. Between January
1, 2024,2025, and December 31, 2024,2025, the adjusted closing price on the NYSE for our common stock ranged between $3.62$6.80 and $9.22.$24.84. The price of our common stock may continue to be
volatile as a result of several factors, some of which are beyond our
control. These factors include, but are not limited to, the following:
In addition, we believe there has been and may continue to be substantial trading in derivatives of our stock, including short selling activity or related similar activities, which are beyond our
our control, and which may be beyond the full control of the SEC and Financial Institutions Regulatory Authority (“FINRA”). While the SEC and FINRA rules prohibit some forms of short selling and other activities that may result in stock price manipulation,
manipulation, such activity may nonetheless occur without detection or enforcement. We have held conversations with regulators concerning trading activity in our stock; however, there can be no assurance that should there be any illegal
manipulation in the trading
of our stock, it will be detected, prosecuted, or successfully eradicated. Significant short sellingshort-selling market manipulation could cause our stock trading price to decline, to become more volatile, or both. For more
information regarding trading in our
common stock and listing on the NYSE,Nasdaq, see additional risk factors included elsewhere in this Annual Report on Form 10-K.
In addition, an entity that, among other things, is or holds itself out as being engaged primarily, or proposes to engage primarily, in the business of investing, reinvesting, owning,
trading, or
holding certain types of securities would be deemed an Investment Company under the Investment Company Act of 1940 (the “1940 Act”). If we do not manage our investments and business in a manner that meets the requirements for an
exemption under the 1940
Act, we may be deemed to be an investment company under the 1940 Act and subject to additional limitations on operating our business including limitations on the issuance of securities, which may make it difficult for
us to raise capital.
Management's Discussion & Analysis (MD&A)
Largest changes
“We continue to augment our product strategy to provide secure AI to the marketplace. …”see in full comparison
“We are developing a Center for Advanced Software and Hardware Integration at our Farmington, Utah facility, that incorporates artificial intelligence (AI) and digital twin technologies alongside our Software-Defined Networks (SDN) capabilities. This facility is intended to support development and integration of secure, adaptive software solutions. …”see in full comparison
“We also support international sales of our commercial products in compliance with applicable U.S. export control laws and regulations, including the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). Our compliance processes are designed to ensure that international transactions adhere to export control requirements while supporting authorized global customers.”see in full comparison
“We hold a Multiple Award Schedule (MAS), enabling streamlined procurement of our products and services by federal, state, and local government customers. We have also obtained Department of Defense Joint Certification Program (DD Form 2345) certifications for our facilities in Zephyr Cove, Nevada, and Farmington, Utah, which permit access to certain unclassified technical data subject to export controls. These certifications support our ability to engage with government and defense customers while maintaining compliance with applicable handling and security requirements.”see in full comparison
“Our employees include the core development team behind our inventions, technology, and software. Some members of this team have worked together for over twenty years and were on the same team that invented and developed this technology while working at Leidos, Inc., or Leidos, (f/k/a Science Applications International Corporation, or SAIC). The team has continued its research and development work to refine our unique network security technology and make it more secure and easy to deploy.”see in full comparison
“Our employees include the core development team behind our inventions, technology, and software. Some members of this team have worked together for over twenty years and were on the same team that invented and developed this technology while working at Leidos, Inc. The team has continued its research and development work to refine our unique network security technology and make it more secure and easy to deploy.”see in full comparison
Full comparison: every changed paragraph (30)
VirnetX Holding Corporation (“Company”, “we”, “us”, or “our”) is an Internet security software and technology company with patented cybersecurity solutions that are designed to ensure resilient, secure communications across any network or device.
We are an Internet security software and technology company with patented technology for Zero Trust Network Access (“ZTNA”) based secure network communications. VirnetX’s software and
technology solutions, including its Secure Domain Name Registry and Technology, VirnetX One™, War Room™, and VirnetX Matrix™ are designed to be device and location-independent, and enable a secure real-time communication environment for all
types of enterprise applications, services, and critical infrastructures. Our technology generates secure connections on a “single-click” basis, significantly simplifying the deployment of secure real-time communication solutions by
eliminating the need for end-users to enter any encryption information.
Our productflagship portfolioplatform, includesVirnetX sophisticatedOne™, technologies,is productsbuilt on Zero Trust Network Access (ZTNA) principles and servicesextends thatour arepatented availableSecure forDomain saleName worldwide.System Our(SDNS) next-generation,technology to establish end-to-end encrypted communications on
demand, regardless of user location or endpoint. VirnetX One™ platformoperates builds upon our patented
Secure Domain Name Registry and Technology to further enhance the security and efficiency of our patented secure communication links. VirnetX One™ isas a security-as-a-service platform thatand protectsmay be deployed in cloud, on-premise, or hybrid enterprise environments. The platform is designed to protect applications, services, and
infrastructure fromby cyber-attacks.providing Ouran platformadditional allowssecurity governmentlayer organizations,that businesses,integrates andwith otherexisting enterprises of all sizessystems to addreduce a “security umbrella” as an added layer on top of their existing infrastructureexposure to furtherevolving reducecyber riskthreats and
bolster security against ever-growing cyberthreats toaffecting data, operating systems, other infrastructure productscomponents, and gateway security controllers.
VirnetX Matrix™ leverages the VirnetX One™ platform to secure communications using encrypted, identity-based access controls, including in contested or high-risk environments. It is designed to protect internet-enabled enterprise applications, connected devices, and control systems, such as file servers, data backup systems, and VPN or firewall environments. VirnetX Matrix™ is intended to be deployed without requiring material changes to an enterprise’s existing infrastructure and provides centralized visibility and policy enforcement to address unauthorized access and evolving attack techniques.
VirnetX War Room™, also built on the VirnetX One™ PLATFORM, provides secure collaboration and visualization capabilities designed to support sensitive, unclassified but secure communications. The platform enables controlled access to virtual meeting environments by validating user and device permissions prior to granting access. VirnetX War Room™ is intended for use cases where confidentiality and access control are critical, including government, law enforcement, legal, financial, and healthcare environments.
Our products, including VirnetX One™, VirnetX Matrix™, and VirnetX War Room™, are designed to support U.S. Department of Defense (DoD), federal government, and commercial customers requiring real-time encrypted communications and network security. We believe our solutions are applicable across a range of public and private sector markets, including critical infrastructure, law enforcement, healthcare, financial services, legal services, energy, and related industries. We pursue sales opportunities nationwide and engage with universities and academic institutions to support research collaboration, workforce development, and technology transition initiatives.
We also support international sales of our commercial products in compliance with applicable U.S. export control laws and regulations, including the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). Our compliance processes are designed to ensure that international transactions adhere to export control requirements while supporting authorized global customers.
Our technology roadmap addresses the continued growth of Internet of Things (IoT) and edge computing environments. We are extending secure networking capabilities to resource-constrained devices through obfuscated and lightweight security mechanisms designed to protect communications without exposing underlying security processes. These efforts support secure identity, trust enforcement, and encrypted communications for distributed and edge-based systems.
We are developing a federated, hybrid mesh network architecture designed with security as a foundational element. This approach incorporates dynamic trust evaluation, autonomous recovery, and distributed decision-making to enhance network resilience and adaptability. We believe this architecture aligns with broader industry trends toward decentralized and resilient network models.
To support system design and evaluation, we employ Model-Based Systems Engineering (MBSE) and agent-based modeling methodologies. These approaches enable simulation and analysis of complex systems, including cyber-physical environments and adaptive networks, and support assessment of system behavior under evolving threat conditions.
We have undertaken efforts to align certain services with the Department of Defense Digital Engineering (DE) strategy. These services are intended to support cybersecurity integration across system design, command and control, battle management, and sensor orchestration, and to enhance our MBSE and cyber threat assessment capabilities. Our Dynamic Trust Evaluation (DTE) methods are designed to enforce trust policies throughout system lifecycles, and our cyber threat intelligence and assessment services provide structured analysis of cyber risks and vulnerabilities.
We intend to make available digital engineering, cyber MBSE, and cyber threat intelligence services to federal, state, and local government agencies, subject to applicable contracting requirements. These services include cybersecurity-focused system design support, advanced modeling of communication flows and threat boundaries, and structured cyber risk assessment methodologies.
We are developing a Center for Advanced Software and Hardware Integration at our Farmington, Utah facility, that incorporates artificial intelligence (AI) and digital twin technologies alongside our Software-Defined Networks (SDN) capabilities. This facility is intended to support development and integration of secure, adaptive software solutions. We have entered into strategic relationships, including an investment in L2 Holdings, LLC (OmniTeq), an AI/Machine Learning (ML) solutions provider and cooperative agreements, including a Cooperative Research and Development Agreement (CRADA) with the Air Force Research Laboratory, Intelligence Systems Directorate (AFRL/RI). The CRADA focuses on cybersecurity and Zero Trust Network Access (ZTNA)-related technologies, extends through 2030, and supports collaboration in areas relevant to defense and intelligence operations.
We hold a Multiple Award Schedule (MAS), enabling streamlined procurement of our products and services by federal, state, and local government customers. We have also obtained Department of Defense Joint Certification Program (DD Form 2345) certifications for our facilities in Zephyr Cove, Nevada, and Farmington, Utah, which permit access to certain unclassified technical data subject to export controls. These certifications support our ability to engage with government and defense customers while maintaining compliance with applicable handling and security requirements.
Durning 2025, we provided subject matter and technical expertise as a subcontractor under a U.S. Department of Defense contract in support of activities directed by the Air Force Research Laboratory (“AFRL”). While there can be no assurance, we believe this engagement may represent a meaningful foothold in the national security sector and may provide pathways to follow-on activities and/or expansion into broader strategic programs.
Our War Room™ software product provides safe and secure video conferencing meeting environment where sensitive communications and data is invisible to those not authorized to view it. War
Room™ validates permissions of all the users, and devices requesting access to any secure meeting room prior to granting access. We believe our War Room™ will be an attractive solution for government and law enforcement agencies as well as
all professional sectors such as legal, financial, and medical where limiting access to confidential data is a critical requirement.
Our VirnetX Matrix™ product provides superior security for internet-enabled enterprise applications and their connected devices, and for control systems currently deployed by those
enterprises (e.g., file servers, data back-up systems, VPN/firewalls). VirnetX Matrix™ provides a true “zero-trust” access protection, “single-click” ease of use, and is a highly-effective added layer of protection that is deployed simply,
without the need for changes to an enterprise’s existing, in-place infrastructure. We believe VirnetX Matrix™ is an attractive solution for all businesses, cloud and on-premise application service providers, and original equipment
manufacturers (“OEMs”), looking to improve visibility and management of their networks to mitigate morphing attacks on their networks and for real time access and control of their users.
We continue to augment our product strategy to provide secure AI to the marketplace. In addition to our investments with L2
Holdings, LLC (“OmniTeq”), an artificial intelligence and machine learning (AI/ML) solutions provider and OP Media, Inc, a dynamic software platform provider, we participated in a Cooperative Research and Development Agreement (CRADA) with
the Air Force (AF) Research Laboratory Intelligence Systems Directorate (AFRL/RI) to facilitate collaboration on cybersecurity and Zero Trust technologies to support integrated surveillance and reconnaissance operations as well as AF and
joint targeting processes. This CRADA continues through 2030 and allows VirnetX to apply for security clearances for its employees. We are also beginning to integrate AI/ML capabilities into VirnetX Matrix™ to enhance its zero-trust security,
threat detection, and network resilience by enabling autonomous threat response, adaptive access control, and self-healing network architectures.
We have undertaken activities to commercialize our products and intellectual property in and outside the United States including
VirnetX One™, War Room™, VirnetX Matrix™ and our Secured Domain Name Registry and Technology. We believe our product portfolio to secure devices and systems are suitable in areas such as national defense, local, state, Federal and foreign
governments, critical infrastructure, law enforcement, healthcare, finance, legal, oil and gas, medical, and related support industries. We continue to actively pursue new sales opportunities in and outside of the United States.
Our employees include the core development team behind our inventions, technology, and software. Some members of this team have worked together for over twenty years and were on the same
team that invented and developed this technology while working at Leidos, Inc., or Leidos, (f/k/a Science Applications International Corporation, or SAIC). The team has continued its research and development work to refine our unique network
security technology and make it more secure and easy to deploy.
Our portfolio of intellectual property portfolio is thea foundationcore component of our business model.business. We currently own U.S. and foreign patents/validations/patents, as well as pending applications. Our patent portfolioapplications, isthat are primarily
focused ondirected to securing real-time communications over the Internet,
Internet and related services,services. andThese ispatents used in allunderpin our technology and products,products. someCertain portions of whichthis portfolio were acquired by our principal operating subsidiary, VirnetX, Inc., from LeidosLeidos, Inc. in 2006.
Our employees include the core development team behind our inventions, technology, and software. Some members of this team have worked together for over twenty years and were on the same team that invented and developed this technology while working at Leidos, Inc. The team has continued its research and development work to refine our unique network security technology and make it more secure and easy to deploy.
We have a facility lease in California, used for corporate, promotionalpromotional, and marketing purposes. The lease expires in 2035.
Investments classified as available-for-sale are recorded at fair market value. Unrealized gains and losses are reported as other comprehensive income. Realized gains and losses are
recorded in
income in the period they are realized using specific identification of each security’s cost basis. We invest our excess cash primarily in highly liquid debt instruments including corporate, government and federal agency
securities, with contractual
maturities less than two years. By policy, we limit the amount of credit exposure to any one issuer.
We have elected the investment measurement alternative for other investments without readily determinable fair values. During 2023, we invested $2,000 in L2 Holdings LLCOmniTeq and $500 in OP
Media Inc. These
investments are carried at our initial cost less any impairment because we do not have the ability to exercise significant influence over operating and financial matters. For these investments, we adjust the carrying value
for any purchases or sales
of our ownership interests. Periodically, we evaluate these investments for impairment. If we identify an impairment, we reduce the carrying value for the impairment loss with a charge to earnings.operating Weexpenses. haveEffective notSeptember 30, 2025 we identified
identified anyan impairment in our investment in OP Media Inc., and as ofa Decemberresult, 31,we 2024.recognized an impairment loss totaling $500.
Revenue generated in 2025 was $162, compared to $5 in 2024. During 2025, we provided subject matter and technical expertise as a subcontractor under a U.S. Department of Defense contract is support of activities directed by AFRL.
Revenue generated in 2024 was $5, compared to $7 in 2023.
Interest and other income in 20242025 was $2,225$1,213 compared to $3,495$2,225 in 2023,2024, due to a decrease in investments.
As of December 31, 2025, our cash and cash equivalents totaled $15,548 and our short-term investments totaled $5,979 compared to $23,296 and $14,786, respectively, as of December 31, 2024.
As of December 31, 2024, our cash and cash equivalents totaled $23,296 and our short-term investments totaled $14,786 compared to $26,289 and $27,258, respectively, as of December 31, 2023.
We expect that our cash and cash equivalents and short-term investments as of December 31, 2024,2025, will be sufficient to fund our current level of selling, general and administration costs and
provide related working capital for the foreseeable
future. Over the longer term, we expect to derive the majority of our future revenue from collaborating with others to integrate our family of cybersecurity products and services into their solutions and to resell
them to their current and future customers as well as from license fees and royalties associated with our patent portfolio, technology, software and secure domain name registry and product sales.registry.
What changed in the latest 10-Q
Risk Factors
Largest changes
see in full comparisonTheBased on the Company’s currentlevelrate of operatingexpenditures,expendituresif continuedand withoutadditionalgivingsourceseffectoftorevenueany future financing orfinancing, would exhaustrevenues, existing liquid resourcesinare projected to be insufficient to sustain the currentsecond quarterlevel of2027,operationsaforperiod of less thantwelve months from the date of issuance ofthethese financialstatements included in this Report on Form 10-Q.statements. Under U.S. GAAP, this condition requires disclosure of substantial doubt about the Company’s ability to continue as a going concern, as set forthforthin the Notes to our condensed consolidated financial statements. This disclosure reflects the application of prescribed accounting standards and is not intended to imply any change in the Company’s expectations regarding its business, strategy or outlook.
We had a net loss ofsee in full comparison$4.4$8.9 million for thequartersix months endedMarchJune31,30, 2026, and a net loss of $18.2 million for the year ended December 31, 2025. As ofMarchJune31,30, 2026, we had an accumulated deficit of$227.2$231.8 million.
The exercise of our outstanding vested stock options and the vesting of RSUs dilutes the ownership interests of our existing stockholders. As ofsee in full comparisonMarchJune31,30, 2026, we had697,758685,339outstanding RSUs andoptions to purchase shares of common stock representing approximately18%17% of our total shares outstanding of which227,490218,337 were vested. To the extent restricted stock is awarded, outstanding stock options are exercised, and RSUs vest, existing stockholders’ percentage voting interests will decline. Also, the number of shares eligible for resale in the public market will increase and such increase may have a negative effect on the value or market trading price of our common stock.
Full comparison: every changed paragraph (8)
TheBased on the Company’s current levelrate of operating expenditures,expenditures if continuedand without additionalgiving sourceseffect ofto revenueany future financing or financing, would exhaustrevenues, existing liquid resources inare projected to be insufficient to sustain the
current second quarterlevel of 2027,operations afor period of less than
twelve months from the date of issuance of thethese financial statements included in this Report on Form 10-Q.statements. Under U.S. GAAP, this condition requires disclosure of substantial doubt about the Company’s ability to continue as a going concern, as set forth
forth in the Notes to our condensed consolidated financial statements. This disclosure reflects the application of prescribed accounting standards and is not intended to imply any change in the Company’s expectations regarding its business,
strategy or
outlook.
We had a net loss of $4.4$8.9 million for the quartersix months ended MarchJune 31,30, 2026, and a net loss of $18.2 million for the year ended December 31, 2025. As of MarchJune 31,30, 2026, we had an accumulated deficit of
$227.2$231.8 million.
The exercise of our outstanding vested stock options and the vesting of RSUs dilutes the ownership interests of our existing stockholders. As of MarchJune 31,30, 2026, we had 697,758685,339 outstanding RSUs and
options to purchase
shares of common stock representing approximately 18%17% of our total shares outstanding of which 227,490218,337 were vested. To the extent restricted stock is awarded, outstanding stock options are exercised, and RSUs vest, existing
stockholders’ percentage
voting interests will decline. Also, the number of shares eligible for resale in the public market will increase and such increase may have a negative effect on the value or market trading price of our common stock.
As of MarchJune 31,30, 2026, our executive officers and directors beneficially owned approximately 16% of our outstanding common stock. Because of their beneficial ownership interest, our officers and
directors could significantly influence stockholder actions. This ability to exercise significant influence could prevent or significantly delay another company from acquiring or merging with us.
To the extent we are unable to secure additional revenue over the next several months, we will need to raise additional capital in the near term. Based on our current level of operating expenditures, we project that our existing cash, cash equivalents and short-term investments will be insufficient to fund the current level of operations, and we have therefore concluded that the conditions for a going concern disclosure under U.S. GAAP are present, as described in the notes to our consolidated financial statements. Our ability to obtain additional capital, if and when required, will depend on our business plans, investor demand, our operating performance, the condition of the capital markets, the terms of our current contractual obligations and other factors.
Changes to U.S. federal, state, and local, and foreign tax laws that may be enacted in the future could impact the tax treatment of our business operations. Our effective tax rate could be adversely
affected by several factors, many of which are outside of our control, including changes in the mix of earnings and losses in countries with differing statutory tax rates, changes in the valuation of deferred tax assets and liabilities, changes in
tax laws, rates, treaties and regulations or the interpretation of the same, changes to the financial accounting rules for income taxes, the outcome of current and future tax audits, examinations or administrative appeals and certain non-deductible
expenses. In addition, many jurisdictions, including the United States, are actively considering changes to existing tax laws or have proposed or enacted new laws, such as the recently enacted U.S. federal tax legislation commonly referred to as
the One Big Beautiful Bill Act (OBBB Act), that could increase our tax obligations in countries where we do business or cause us to change the way we operate our business. We are currently evaluating the full impact of the OBBB Act on us. As of
MarchJune 31,30, 2026, the OBBB Act has had no material income tax impact on our financial statements.
In addition, the Organization for Economic Cooperation and Development has proposed imposing a 15% global minimum tax under the Pillar Two Model Rules (Pillar Two), and this proposal has been adopted
or is being considered by a number of countries, which could impact our business if we expand internationally. However, on June 28, 2025, the G7 released a joint statement that it had reached an understanding with the United States for a
side-by-side system based on certain accepted principles, including that U.S.-parented groups, such as ours, would be exempt from certain provisions of Pillar Two. Any of these developments or changes in U.S. federal, state or international tax
laws or tax rulings could adversely affect our effective tax rate and our operating results. As of MarchJune 31,30, 2026, we are not yet subject to Pillar Two due to the level of gross receipts.
Our common stock is currently listed on the Nasdaq Stock Market LLC (Nasdaq) and was previously listed on NYSE and NYSE American LLC (formerly the NYSE MKT LLC). Over the past year, the market price
of our common stock has experienced significant fluctuations. Between AprilJuly 1, 2025, and MarchJune 31,30, 2026, the adjusted closing price for our common stock ranged between $7.50$11.37 and $24.84. The price of our common stock may continue to be volatile as a
result of several factors, some of which are beyond our control. These factors include, but are not limited to, the following:
Management's Discussion & Analysis (MD&A)
Largest changes
“VirnetX iSCOUT (IoT System for Connected Object Understanding and Telemetry) leverages a common, secure IoT and data infrastructure to fuse sensor, geospatial, and agency data into a unified operating picture, including in disaster response and smart city environments. …”see in full comparison
“As of June 30, 2026, our cash and cash equivalents totaled approximately $13,090 and our short-term investments totaled approximately $799, compared to cash and cash equivalents of approximately $15,548 and short-term investments of approximately $5,979 at December 31, 2025, respectively. Working capital was $11,847 at June 30, 2026.”see in full comparison
Our research and development expensessee in full comparisonremaineddecreasedsteadyslightlybetweenin 2026andcompared2025to 2025, totaling$1,162$1,126 and$1,259$1,215 for the three months endedMarchJune31,30, 2026 and 2025,respectively.and totaling $2,288 and $2,474 for the six months ended June 30, 2026 and 2025. The decrease was related to compensation.
“On June 2, 2026, the SEC declared our shelf registration statement of Form S-3 effective (File No. 333-295960). The S-3 covers the offer and sale up to $20 million in securities in one or more offerings, in amounts, at prices and on terms determined at the time of the offering.”see in full comparison
Our selling, general and administrative expenses increasedsee in full comparisonfrom$749$2,788andto$1,308$3,346 forin the three and six months endedMarchJune31,30,2026,2026 compared to 2025. The variance was primarily related tocompensationincreasesexpenseof $388 in legal expenses, $362 in equity compensation, andcorporate$395travel.in travel expense.
We intend to make available our digital engineering, cyber MBSE, and cyber threat intelligence services to federal, state, and local government agencies, subject to applicable contracting requirements. We hold a Multiple Award Schedule (MAS) and obtained DoD Joint Certification Program (DD Form 2345) certifications for our facilities in Zephyr Cove, Nevada, and Farmington, Utah, which permit access to certain unclassified technical data subject to export controls.see in full comparisonThese certifications streamline procurement of our products and services by federal, state, and local government agencies and support our ability to engage with government and defense customers while maintaining compliance with applicable handling and security requirements.
Full comparison: every changed paragraph (13)
VirnetX War Room™ is also built on the VirnetX One™ platform, provides secure collaboration and visualization capabilities designed to support sensitive, unclassified but secure communications. The platform enables controlled access to virtual meeting environments by validating user and device permissions prior to granting access. VirnetX War Room™ is intended for use cases where confidentiality and access control are critical, including government, law enforcement, legal, financial, and healthcare environments.
VirnetX iSCOUT (IoT System for Connected Object Understanding and Telemetry) leverages a common, secure IoT and data infrastructure to fuse sensor, geospatial, and agency data into a unified operating picture, including in disaster response and smart city environments. It is designed to support mission-specific applications that can be customized for a range of markets, with two initial implementations currently in development: a Humanitarian Assistance Disaster Relief–Emergency Response (HADR-ER) capability that provides federal, state, and local partners with a real-time operating picture for national emergency management, and a smart city solution for international markets, including Japan, tailored to urban resilience, mobility, and critical infrastructure monitoring in dense metropolitan environments. VirnetX iSCOUT is intended to be deployed as a shared, exportable technology stack, with each application configured for its distinct mission, and we may pursue additional customized applications for other markets in the future.
We intend to make available our digital engineering, cyber MBSE, and cyber threat intelligence services to federal, state, and local government agencies, subject to applicable contracting
requirements. We hold a Multiple Award Schedule (MAS) and obtained DoD Joint Certification Program (DD Form 2345) certifications for our facilities in Zephyr Cove, Nevada, and Farmington, Utah, which permit access to certain unclassified technical
data subject to export controls. These certifications streamline procurement of our products and services by federal, state, and local government agencies and support our ability to engage with government and defense customers while maintaining
compliance with applicable handling and security requirements.
Three and Six Months Ended MarchJune 31,30, 2026
Compared with the Three and Six Months Ended MarchJune 31,30, 2025
We recognized norevenue revenue$48 in the three months and six months ended MarchJune 31,30, 20262025 and 2025.no revenue during the same periods in 2026.
Our research and development expenses remaineddecreased steadyslightly betweenin 2026 andcompared 2025to 2025, totaling $1,162$1,126 and $1,259$1,215 for the three months ended MarchJune 31,30, 2026 and 2025, respectively.and totaling $2,288 and $2,474 for the six months ended June 30, 2026 and 2025. The
decrease was related to compensation.
Our selling, general and administrative expenses increased from$749 $2,788and to$1,308 $3,346 forin the three and six months ended MarchJune 31,30, 2026,2026 compared to 2025. The variance was primarily related to compensationincreases expenseof
$388 in legal expenses, $362 in equity compensation, and corporate$395 travel.in travel expense.
As of June 30, 2026, our cash and cash equivalents totaled approximately $13,090 and our short-term investments totaled approximately $799, compared to cash and cash equivalents of approximately $15,548 and short-term investments of approximately $5,979 at December 31, 2025, respectively. Working capital was $11,847 at June 30, 2026.
As of March 31, 2026, the Company held approximately $17.2 million in cash, cash equivalents and short-term investments.
Based on the Company’s current rate of operating expenditures and without giving effect to any future financing or additional revenue, existing liquid resources are projected to be insufficient to
sustain the current
level of operations through May 2027, a period of less thanfor twelve months from the date of issuance of these financial statements. This condition triggers the going concern disclosure requirements under U.S. GAAP and as required, is described in
notes to our
condensed consolidated financial statements. Management intends to continue pursuit of cash generation via revenue sources and financing.
On June 2, 2026, the SEC declared our shelf registration statement of Form S-3 effective (File No. 333-295960). The S-3 covers the offer and sale up to $20 million in securities in one or more offerings, in amounts, at prices and on terms determined at the time of the offering.
Our effective tax rate is 0% for income tax for the three and six months ended MarchJune 31,30, 2026 and 2025, and we expect our effective tax rate for the full year will be 0%. Our effective tax rate is less
than the 21% statutory
tax rate primarily due to our valuation allowance. Based on the weight of available evidence, including net cumulative losses and expected future losses, we have determined it is more likely than not that our U.S. federal and
state deferred tax
assets will not be realized and therefore we have provided a full valuation allowance on the U.S. federal and state net deferred tax assets.
VHC insider buying and selling (Form 4)
Since 2026-04-11, insiders reported open-market purchases in 0 Form 4 filings and open-market sales in 4 filings (3 insiders, 7 trade dates, 43,500 shares, about $489.1K; 4 of these filings say the sales were made under a Rule 10b5-1 trading plan). Net open-market shares: -43,500 (purchases minus sales); net value about -$489.1K.Totals add up every open-market (code P and S) line in those filings, using the prices reported in the filings. Awards, option exercises, tax withholding and gifts are listed below but not counted.
| Trade date | Insider | Transaction | Shares | Price | Value |
|---|---|---|---|---|---|
| 2026-09-30 | Angelo Michael F |
Open-market sale |
1,000 | $10.26 | $10.3K |
| 2026-09-14 | Larsen Kendall |
Open-market sale |
4,425 | $11.17 | $49.4K |
| 2026-09-11 | Larsen Kendall |
Open-market sale |
8,000 | $11.37 | $91.0K |
| 2026-09-10 | Larsen Kendall |
Open-market sale |
8,000 | $11.48 | $91.8K |
| 2026-09-02 | Larsen Kendall |
Open-market sale |
4,057 | $11.43 | $46.4K |
| 2026-09-02 | Larsen Kendall |
Open-market sale |
518 | $12.13 | $6.3K |
| 2026-09-01 | Larsen Kendall |
Open-market sale |
5,000 | $11.00 | $55.0K |
| 2026-09-01 | Feiner Gary |
Open-market sale |
3,750 | $11.00 | $41.2K |
| 2026-08-31 | Larsen Kendall |
Open-market sale |
5,000 | $11.17 | $55.9K |
| 2026-08-31 | Feiner Gary |
Open-market sale |
3,749 | $11.17 | $41.9K |
| 2026-08-31 | Feiner Gary |
Open-market sale |
1 | $12.03 | $12 |
| 2026-07-06 | Allanson Katherine |
Shares withheld for tax | 100 | $11.95 | $1.2K |
| 2026-06-11 | O'brien Thomas M |
Grant/award | 7,500 | — | — |
| 2026-06-11 | Angelo Michael F |
Grant/award | 7,500 | — | — |
| 2026-06-11 | Chow Heidy Kingwan |
Grant/award | 7,500 | — | — |
| 2026-06-11 | Feiner Gary |
Grant/award | 7,500 | — | — |
Well-known investors holding VHC (13F)
None of the 59 investors we track reported a position in their latest 13F.