Companies › VHC

VHC 10-K & 10-Q changes, risk factors and insider trading

VirnetX Holding Corp · Nasdaq · Patent Owners & Lessors · CIK 1082324 · All filings on SEC.gov

Everything below is quoted or computed from VirnetX Holding Corp's public SEC filings. It is not a recommendation to buy or sell. Automated comparisons can contain errors; confirm with the original filing.

At a glance

12 / 7risk-factor paragraphs added / removed in latest 10-K
3new risk-factor headings
0Form 4 filings reporting open-market purchases (last 180 days)
4Form 4 filings reporting open-market sales (last 180 days)

Jump to: Annual report (10-K) · Quarterly report (10-Q) · Insider transactions · 13F holders

What changed in the latest 10-K

Comparing 10-K filed 2026-03-24 (period ending 2025-12-31) with 10-K filed 2025-03-17 (period ending 2024-12-31).

Risk Factors (10-K Item 1A)

12new paragraphs
7removed paragraphs
24reworded paragraphs
7,347 → 7,467words in section

New heading “We plan to offer our products to government entities, which are subject to a number of challenges and risks.”

New heading “Our business could be adversely affected if our employees cannot obtain and maintain required personnel security clearances or we cannot establish and maintain a required facility security clearance.”

New heading “Changes in tax law could materially impact our business, results of operations and financial condition.”

Removed heading “Our business has been, and may continue to be, negatively affected by activist shareholders.”

Removed heading “Failure to meet the NYSE’s continued listing requirements could result in the suspension of trading of our common stock and a subsequent delisting of our common stock.”

Largest changes (selected automatically by length and topic keywords; quoted verbatim, no commentary)

Removed text topics: delist
“Failure to meet the NYSE’s continued listing requirements could result in the suspension of trading of our common stock and a subsequent delisting of our common stock.”
see in full comparison
Removed text topics: delist, liquidity
“If shares of our common stock are delisted from the NYSE, there may be no public market for our common stock. Any over-the-counter or other market that does develop would likely be characterized by decreased liquidity and greater volatility, which may materially and adversely affect the value of our common stock. …”
see in full comparison
New text topics: department of justice, regulation
“The U.S. Department of Justice has also issued regulations regarding certain bulk sensitive personal data transfers. We cannot yet fully determine the impact these or future laws, regulations and standards may have on our business, but they may require us to modify our data processing practices and policies and to incur substantial costs and expenses in efforts to comply. …”
see in full comparison
Removed text topics: delist
“Our common stock could also be delisted if our average global market capitalization over a consecutive 30 trading-day period is less than $15 million. Our average global market capitalization over a consecutive 30 trading-day period may fall below $15 million based on continued volatility and fluctuations in the market price of our common stock. …”
see in full comparison
New text
“Our business could be adversely affected if our employees cannot obtain and maintain required personnel security clearances or we cannot establish and maintain a required facility security clearance.”
see in full comparison
New text
“We plan to offer our products to government entities, which are subject to a number of challenges and risks.”
see in full comparison
Full comparison: every changed paragraph (43)

Green = added, red = removed. Unchanged paragraphs and tables are not shown. Read the complete text in the original filing.

Reworded

Our operating results may not be consistent and may be difficult to predictpredict, and we may not be able to achieve or sustain profitability in the future.

Reworded

We had a net loss of $6.2$18.2 million for the quarteryear ended December 31, 2024.2025 We hadand a net loss of $18.2 million for the year ended December 31, 2024. As of December 31, 2024,2025, we had an accumulated deficit of $204.7$222.9 million. Our operating results have fluctuated in the past due to several factors and may fluctuate in the future due to the same or similar factors, which include but are not limited to the following:

Added

Our operating results have fluctuated in the past due to several factors and may fluctuate in the future due to the same or similar factors, which include but are not limited to the following:

Reworded

These fluctuations may make our business particularly difficult to manage, adversely affect our business and operating results, make our operating results difficult for investors to predict and, and, further, cause our results to fall below investor’s expectations and adversely affect the market price of our common stock. If we fail to increase our revenue to offset any increases in our operating expenses,revenue, we may not achieve or sustain profitability in the future.

Reworded

Part of ourOur business strategy is to enter into partnerships, strategic investments, and other cooperative arrangements with other companies and government agencies. We have invested in and we continue to seek to invest in or acquire businesses, technologies, or other assets that we believe could complement or expand our business. In addition, we are regularly involved in cooperative efforts with respect to the incorporation of our products into products of others and vice versa, collaborative research and development efforts with government and university laboratories, distributor and reseller arrangements and service provider partnerships. These relationships are generally non-exclusive, and some of our partners also have cooperative relationships with certain of our competitors or offer some products and services that are competitive with ours. If we lose third-party relationships, if these relationships are not commercially successful, or if we are unable to enter into third-party relationships on commercially reasonable terms in the future, our business could be negatively impacted.

Reworded

The sales cycle between initial customer contact and the execution of a contract or license agreement with a customer or purchaser of our products can vary widely. We expect that our sales cycles will be long and unpredictable due to several factors, including but not limited to:

Added

We plan to offer our products to government entities, which are subject to a number of challenges and risks.

Added

Government entities have announced reductions in, or experienced increased pressure to reduce, government spending. Continued U.S. debt, income tax and budget issues, government shutdowns and delays in approving U.S. spending or reductions in such may adversely impact existing or future U.S. public sector transactions and affect future sales of our products and services to such entities. Additionally, any future government demand and payment for our products may be more volatile as they are affected by public sector budgetary cycles, funding authorizations, and the potential for funding reductions or delays, making the time to close such transactions more difficult to predict.

Added

In addition, sales to government entities are subject to a number of risks. Government entities may continue use of legacy products and services indefinitely and be slow to transition to more modern products and services, including ours, or impose challenging regulatory requirements on such adoptions, any of which may inhibit the growth of our public sector business. Selling to government entities can be highly competitive, expensive and time consuming, often requiring significant upfront time and expense without any assurance that we will successfully sell our products to such governmental entity. Government entities may require contract terms that differ from our standard arrangements or require the maintenance of certain facility and employee security clearance, which may be difficult to obtain or maintain.

Added

Our business could be adversely affected if our employees cannot obtain and maintain required personnel security clearances or we cannot establish and maintain a required facility security clearance.

Added

Certain government contracts may require our employees to maintain various levels of security clearances and may require us to maintain a facility security clearance to comply with U.S. and international government agency requirements. Many governments have strict security clearance requirements for personnel who perform work in support of classified programs. Obtaining and maintaining security clearances for employees typically involves a lengthy process, and it can be difficult to identify, recruit, and retain employees who already hold security clearances. If our employees are unable to obtain security clearances in a timely manner, or at all, or if our employees who hold security clearances are unable to maintain their clearances or terminate employment with us, then we may be unable to bid on or win new classified contracts. To the extent we are not able to obtain or maintain a facility security clearance, we may not be able to bid on or win classified contracts, which would have an adverse impact on our business, financial condition, and results of operations.

Reworded

We have limited technical resources and are at an early stage in commercialization of our VirnetX One™ platform and software products.products, as well as our DE, DTE methods, MBSE, and cyber threat assessment services.

Added

The market for ZTNA security solutions is rapidly evolving and highly competitive as new entrants and traditional network solutions companies offer cloud-based cybersecurity solutions. Competition in our business is highly diverse, and while our competitors offer different products and services, there is often competition for contracts that are part of government budgets. We also may face competition from companies that provide products and services to the U.S. Government, including defense contractors.

Reworded

TheMany market for ZTNA security solutions is rapidly evolving and highly competitive as new entrants and traditional network solutions companies offer cloud-based cybersecurity solutions. Many of our competitors and potential competitors have established brand recognition, larger customer bases, and greater resources than we do. Our primary competitors in the ZTNA market include Appgate, Cloudflare, and Illumio. In the enterprise market, our primary competitors include Zscaler (ZPA), Palo Alto Networks (Prisma Access), Cisco (Umbrella), Citrix (Secure Private Access), Netskope (Private Access for ZTNA) and Cato Networks. As we expand our product offerings and use cases, we will begin to compete with companies that offer bundled security-as-a-service solutions that include Secure Access Service Edge (SASE) and Security Service Edge (SSE). With the introduction of new technologies and market entrants, we expect competition to intensify in the future. For example, disruptive technologies such as generative AI has and may continue to fundamentally alter the market for our services in unpredictable ways and reduce customer demand. If we fail to compete effectively, our business will be harmed. Some of our competitors offer their products or services at lower prices or for free as part of a broader bundled product sale or enterprise license arrangement, which has placed pricing pressure on our business. If we are unable to achieve our target pricing levels, our operating results will be negatively impacted. For us to compete effectively, we need to introduce new products and services in a timely and cost-effective manner, meet customer expectations and needs at prices that customers are willing to pay, and continue to enhance the features and functionalities of our cloud content management platform. In addition, pricing pressures and increased competition could result in reduced sales, lower margins, losseslosses, or the failure of our services to achieve or maintain widespread market acceptance, any of which could harm our business.

Reworded

Many of our competitors are able to devote greater resources to the development, promotion and sale of their products or services. In addition, many of our competitors have established marketing marketing relationships and major distribution agreements with government agencies, channel partners, consultants, system integratorsintegrators, and resellers. Competitors may offer products or services at lower prices or with greater depth than our services. Our competitors may be able to respond more quickly and effectively to new or changing opportunities, technologies, standardsstandards, or customer requirements. Furthermore, some potential customers, particularly large enterprises, may elect to develop their own internal solutions. In addition, the U.S. government and foreign governments may develop, construct, launch and operate their own ZTNA security solutions with capabilities comparable or similar to ours, which could reduce their need to rely on us and other commercial suppliers. For any of these reasons, we may not be able to compete successfully against our competitors.

Reworded

Our products are highly technical and complex and, when deployed, may contain errors or defects. Despite testing, some errors in our products may only be discovered after a product has been installed and used by customers. Any errors or defects discovered in our products after commercial release could result in failure to achieve market acceptance, loss of revenue or delay in revenue recognition, loss of customers and increased service and warranty cost, any of which could adversely affect our business, operating results, and financial condition. In addition, we could face claims for product liability, tort, or breach of warranty, including claims relating to changes to our products made by our channel partners. The performance of our products could have unforeseen or unknown adverse effects on the networks over which they are delivered as well as on third-party applications and services that utilize our services, which could result in legal claims against us,us harming our business. Furthermore, we expect to provide implementation, consulting, and other technical services in connection with the implementation and ongoing maintenance of our products, which typically involves working with sophisticated software, computing, and communications systems. We expect that our contracts with customers will contain provisions relating to warranty disclaimers and liability limitations, which may may not be upheld. Defending a lawsuit, regardless of its merit, is costly and may divert management’s attention and adversely affect the market’s perception of us and our products. In addition, if our business liability insurance coverage proves proves inadequate or future coverage is unavailable on acceptable terms or at all, our business, operating results, and financial condition could be adversely impacted.

Reworded

Our business will depend upon, among other things, the capacity, reliability, security, and unimpeded access of the infrastructure owned by third parties that we will use to deploy our offerings. offerings. We have no control over the operation, quality, or maintenance of a significant portion of that infrastructure or whether those third parties will upgrade or improve their equipment. We depend on these companies to maintain the operational integrity of our connections. If one or more of these companies is unable or unwilling to supply or expand their levels of service to us in the future, our operations could be severely interrupted. Also, to the extent that the number of users of networks utilizing our current or future products suddenly increases, the technology platform and secure hosting services which will be required to accommodate a higher volume of traffic may result in slower response times or service interruptions. System interruptions or increases in response time could result in a loss of potential or existing users and, if sustained or repeated, could reduce the appeal of the networks to users. In addition, users depend on real-time communications; outages caused by increased traffic could result in delays and system failures. These types of occurrences could cause users to perceive that our solution does not function properly and could therefore adversely affect our ability to attract and retain licensees, strategic partners, and customers.

Reworded

We face security threats from malicious third parties that could obtain unauthorized access to our systems, network, and data. We expect to retain certain confidential and proprietary customer information in our secure data centers and secure domain name registry, as well as personal data and other confidential and proprietary information relating to our business. It will be critical to our business strategy that our facilities and infrastructure, including our secure domain name servers, remain secure and are perceived by the marketplace to be secure. Our secure domain name registry operations will also depend on our ability to maintain our computer and telecommunications equipment in effective working order and to reasonably protect our systems against interruption, and potentially depend on protection by other registrars in the shared registration system..system. Additionally, we maintain confidential and proprietary business information, including trade secrets. We expect to continue to have to expend significant time and money to maintain or increase the security of our products, facilities, and infrastructure. Security technologies are constantly being tested by computer professionals, academics and “hackers.” Advances in computer capabilities and the techniques for attacking security solutions, new discoveries in the field of cryptography or other events or developments could result in compromises or breaches of our security measures and could make some or all our products obsolete or unmarketable. Likewise, we may need to dedicate engineering and other resources to mitigate or eliminate security vulnerabilities and may find it necessary or appropriate to repair or replace products already sold or licensed to our customers. Despite the security measures that we and our service providers utilize, our infrastructure and that of our service providers may be vulnerable to physical break-ins, ransomware, computer viruses, other malicious code attacks by hackers, phishing attacks, social engineering, or similar disruptive problems. There can be no assurances our security measures or those of our service providers will prevent security breaches or incidents. Any disruption or security breach or incident that we or our service providers suffer or are perceived to suffer, including any such disruption, breach or incident resulting in a loss of, or damage to, data or systems, or inappropriate disclosure, access, loss, or other processing of confidential, financial, proprietary or personal information, including data related to our personnel, could result in loss, disclosure or other unauthorized processing of such data, could delay our research and development or commercialization efforts, could compel us to comply with breach notification laws and regulations, subject us to mandatory corrective action, and otherwise subject us to liability under laws and regulations that protect the privacy and security of personal information. It is possible that we may have to expend additional financial and other resources to address such problems. Remote work by our personnel and those of third parties has resulted in increased vulnerability to cyber-attacks. Additionally, geopolitical tensions and conflicts may create increased risks of cyber-attacks. As a provider of Internet security software and technology, we may be the target of dedicated efforts by hackers and other third parties to overcome or defeat our security measures. Any physical or electronic break-in or other security breach or incident or compromise impacting our products, or any information stored at our secure data centers and domain name registration systems, including any compromise due to human error or employee or contractor malfeasance, may jeopardize the security of information stored on our premises or in the computer systems and networks of our customers. Additionally, any such data security incident, or the perception that one has occurred could also result in adverse publicity, harm to our reputation and competitive position, and therefore adversely affect the market’s perception of the security of electronic commerce and communications over IP networks as well as the security or reliability of our services, which could have a material adverse impact on our business, financial condition, and results of operations.

Added

Additionally, during times of war and other geopolitical tensions and conflicts may create increased risks of cyber-attacks. As a provider of Internet security software and technology, we may be the target of dedicated efforts by hackers and other third parties to overcome or defeat our security measures. Any physical or electronic break-in or other security breach or incident or compromise impacting our products, or any information stored at our secure data centers and domain name registration systems, including any compromise due to human error or employee or contractor malfeasance, may jeopardize the security of information stored on our premises or in the computer systems and networks of our customers. Additionally, any such data security incident, or the perception that one has occurred could also result in adverse publicity, harm to our reputation and competitive position, and therefore adversely affect the market’s perception of the security of electronic commerce and communications over IP networks as well as the security or reliability of our services, which could have a material adverse impact on our business, financial condition, and results of operations.

Reworded

A security breach or other security incident, or the perception any such event has occurred, could require a substantial level of financial resources to address and otherwise respond to, may be be difficult to identify or address in a timely manner, and could result in claims, investigations, inquiries, and other proceedings or actions by private parties or governmental entities that may divert management’s attention and require the expenditure of significant time and resources, and which may cause us to incur substantial fines, penalties, or other liability and related legal and other costs. Cybersecurity risks pose a particularly significant risk to our business given our our focus on providing internet security software and secure communications technology. Any actual or perceived security breach or other security incident may also harm our reputation, result in a loss of customers, and make it more difficult or or impossible for us to successfully market to others. Any of the foregoing matters could harm our business, operating resultsresults, and financial condition.

Reworded

Privacy and data security concerns, data collectioncollection, and transfer restrictions and related domestic or foreign regulations may limit the use and adoption of of our solutions and adversely affect our business.

Reworded

Further, many foreign countries and governmental bodies, including the European Union (“EU”), where we conduct business, have laws and regulations concerning the collection and use of personal data obtained from their residents or by businesses operating within their jurisdiction. These laws and regulations often are more restrictive than those in the United States. Laws and regulations in these jurisdictions apply broadly to the collection, use, storage, disclosure, and security of data that identifies or may be used to identify or locate an individual.

Reworded

We also expect that there will continue to be new proposed laws, regulations and industry standards concerning privacy, data protection and information security in the United States, the EU, and and other jurisdictions. For example, the European Commission maintains a General Data Protection Regulation (the “GDPR”) that imposes stringent data protection requirements and provides for substantial penalties for noncompliance. The United Kingdom has enacted a Data Protection Act and legislation referred to as the UK GDPR that substantially implements the GDPR and provides for a penalty regime similar to the GDPR. The United Kingdom made targeted amendments to the Data Protection Act and the UK GDPR in the UK Data (Use and Access) Act, effective June 19, 2025. We may be required to incur substantial expense in order to make significant changes to our products and operations to address compliance with the GDPR and similar legislation, such as the UK GDPR and UK Data Protection Act, all of which may adversely affect our revenue and product sales. California has enacted legislation, the California Consumer Privacy Act (the “CCPA”) that, among other things, requires covered companies to provide disclosures to California consumers, and afford such consumers abilities to opt-out of certain sales of personal information. The CCPA was modified and expanded by the California Privacy Rights Act (the “CPRA”), which was approved by California voters in the November 2020 election. Additionally, other U.S. states continue to propose, and in certain cases adopt, privacy-focused legislation. For example, Connecticut, Virginia, UtahUtah, and Colorado enacted legislation similar to the CCPA and CPRA that took effect in 2023; Florida, Montana, Oregon, and Texas have enacted similar legislation that has becamebecome effective in 2024; Delaware, Nebraska, Maryland, New Hampshire, New Jersey, Minnesota, Tennessee, and Iowa have enacted similar legislation that has or will become effective in 2025;legislation, and Indiana, Kentucky, and Rhode Island have enacted similar legislation that willhas become effective in 2026. We cannot yet fully determine the impact these or future laws, regulations and standards may have on our business, but they may require us to modify our data processing practices and policies and to incur substantial costs and expenses in efforts to comply. Privacy, data protection and information security laws and regulations are often subject to differing interpretations, may be inconsistent among jurisdictions, and may be alleged to be inconsistent with our current or future practices. Additionally, we may be bound by contractual requirements applicable to our collection, use, processing, and disclosure of various types of data, including personal data, and may be bound by, or voluntarily comply with, self-regulatory or other industry standards relating to these matters. These and other requirements could reduce demand for our products, increase our costs, impair our ability to grow our business, or restrict our ability to store and process data or, in some cases, impact our ability to offer our service in some locations and may subject us to liability. Any failure or perceived failure to comply with applicable laws, regulations, industry standards, and contractual obligations may adversely affect our business. Further, in view of new or modified federal, state, or foreign laws and regulations, industry standards, contractual obligations and other legal obligations, or any changes in their interpretation, we may find it necessary or desirable to fundamentally change our business activities and practices or to expend significant resources to modify our product and otherwise adapt to these changes. We may be unable to make such changes and modifications in a commercially reasonable manner or at all, and our ability to develop new products and features could be limited.

Added

The U.S. Department of Justice has also issued regulations regarding certain bulk sensitive personal data transfers. We cannot yet fully determine the impact these or future laws, regulations and standards may have on our business, but they may require us to modify our data processing practices and policies and to incur substantial costs and expenses in efforts to comply. Privacy, data protection and information security laws and regulations are often subject to differing interpretations, may be inconsistent among jurisdictions, and may be alleged to be inconsistent with our current or future practices. Additionally, we may be bound by contractual requirements applicable to our collection, use, processing, and disclosure of various types of data, including personal data, and may be bound by, or voluntarily comply with, self-regulatory or other industry standards relating to these matters. These and other requirements could reduce demand for our products, increase our costs, impair our ability to grow our business, or restrict our ability to store and process data or, in some cases, impact our ability to offer our service in some locations and may subject us to liability. Any failure or perceived failure to comply with applicable laws, regulations, industry standards, and contractual obligations may adversely affect our business. Further, in view of new or modified federal, state, or foreign laws and regulations, industry standards, contractual obligations and other legal obligations, or any changes in their interpretation, we may find it necessary or desirable to fundamentally change our business activities and practices or to expend significant resources to modify our product and otherwise adapt to these changes. We may be unable to make such changes and modifications in a commercially reasonable manner or at all, and our ability to develop new products and features could be limited.

Removed

Our business has been, and may continue to be, negatively affected by activist shareholders.

Removed

Responding to actions and communications by activist shareholders is costly and time-consuming, has diverted the attention of management, our Board of Directors and our employees, and may be disruptive to our operations. Additionally, perceived uncertainties as to our future direction as a result of shareholder activism may lead to the perception of a change in the direction of our business or other instability, which may be exploited by our competitors, cause concern to our current or potential customers, and make it more difficult to attract and retain qualified personnel. Furthermore, if customers choose to delay, defer or reduce transactions with us or do business with our competitors instead of us, then our business, financial condition and operating results would be adversely affected. In addition, our share price could experience periods of increased volatility as a result of shareholder activism.

Reworded

The exercise of our outstanding stock options and warrants, and the issuance of RSUs and restricted stock would result in a dilution of our current stockholders’ voting power and an increase in the number of shares eligible for future resale in the public market which may negatively impact the market price of our stock.

Reworded

The exercise of our outstanding vested stock options and warrants, and the vesting of RSUs and restricted stock dilutes the ownership interests of our existing stockholders. As of December 31, 2024,2025, we had 727,884 outstanding options, warrantsoptions and RSUs to purchase an aggregate of 265,040 shares of common stock representing approximately 6.25%18% of our total shares outstanding of which 242,352234,842 were vested. To the extent restricted stock is awarded, outstanding stock options or warrants are exercised exercised, and RSUs vest, additional shares of common stock will be issued, existing stockholders’ percentage voting interests will declinedecline. andAlso, the number of shares eligible for resale in the public market will increase. Suchincrease and such increase may have a negative effect on the value or market trading price of our common stock.

Reworded

As of December 31, 2024,2025, our executive officers and directors beneficially owned approximately 18%16% of our outstanding common stock. Because of their beneficial ownership interest, our officers and directors could significantly influence stockholder actions of which you disapprove or that are contrary to your interests.actions. This ability to exercise significant influence could prevent or significantly delay another company from acquiring or merging with us.

Reworded

We have protective provisions in our amended and restated certificate of incorporation (“Restated Charter”) and amended and restated bylaws (“Restated Bylaws”) that could delay, discourage, or prevent a third party from acquiring control of us without the approval of our Board of Directors. These protective provisions include:

Removed

In addition, the provisions of Section 203 of the Delaware General Corporation Law govern us. These provisions may prohibit large stockholders, particularly those owning 15% or more of our outstanding voting stock, from merging or combining with us for a certain period of time.

Reworded

In addition, the provisions of Section 203 of the Delaware General Corporation Law govern us. These provisions may prohibit large stockholders, particularly those owning 15% or more of our outstanding voting stock, from merging or combining with us for a certain period of time. These and other provisions in our Restated Charter, our Restated Bylaws and under Delaware law could discourage potential takeover attempts, reduce the price that investors might be willing to pay for shares of our common stock in the future and result in the market price being lower than it would be without these provisions.

Removed

Failure to meet the NYSE’s continued listing requirements could result in the suspension of trading of our common stock and a subsequent delisting of our common stock.

Removed

On August 28, 2024, we received a written notification from the NYSE that as of August 27, 2024, we were not in compliance with the continued listing standards set forth in Section 802.01B of the NYSE Listed Company Manual because the average global market capitalization over a consecutive 30 trading-day period and stockholders’ equity were both less than $50 million. In accordance with applicable NYSE procedures, we submitted a plan to the NYSE on October 11, 2024, and provide quarterly updates advising it of the definitive actions we have taken, are taking and plan to take that would bring us into conformity with the standard set forth in Section 801.01B within 18 months of receipt of the written notification. The written notification has no immediate impact on our ongoing business operations, reporting requirements with the SEC or the listing of our common stock on the NYSE at this time, subject to the Company’s continued compliance with the plan and NYSE’s other continued listing standards. We are considering all available options to regain compliance with NYSE’s continued listing standards but can provide no assurances that we will be able to satisfy the requirements of the NYSE.

Removed

Our common stock could also be delisted if our average global market capitalization over a consecutive 30 trading-day period is less than $15 million. Our average global market capitalization over a consecutive 30 trading-day period may fall below $15 million based on continued volatility and fluctuations in the market price of our common stock. In the event that our stock price does not meet the global market capitalization requirement, the NYSE will promptly suspend our common stock from trading on the NYSE and will simultaneously begin the process to delist our common stock, subject to our right to appeal under NYSE rules. While we may appeal this decision, there is no assurance that any appeal we undertake will be successful.

Removed

If shares of our common stock are delisted from the NYSE, there may be no public market for our common stock. Any over-the-counter or other market that does develop would likely be characterized by decreased liquidity and greater volatility, which may materially and adversely affect the value of our common stock. A delisting of our common stock could negatively impact the Company and holders of our common stock, including by reducing the willingness of investors to hold our common stock because of the resulting decreased price, liquidity and trading of our common stock, limited availability of price quotations, and reduced news and analyst coverage. These developments may also require brokers trading in our common stock to adhere to more stringent rules and may limit our ability to raise capital by issuing additional shares of common stock in the future. Delisting may adversely impact the perception of our financial condition, cause reputational harm with investors, our employees and parties conducting business with us, and limit our access to debt and equity financing. The perceived decrease in value of employee equity incentive awards may reduce their effectiveness in encouraging performance and retention.

Reworded

Our business may be adversely affected by instability, disruption, or destruction in a geographic region in which we operate, regardless of cause, including war, terrorism, riot, civil insurrection, or social unrest, and natural or manmade disasters, including famine, flood, fire, earthquake, storm, or pandemic events and spread of disease. Our business may also be adversely affected by further downturn in macroeconomic conditions, conditions, including inflation and rising interest rates, tariffs, trade wars, global political and economic uncertainty and tensions, such as the ongoing Russia-Ukraine and Israel-HamasMiddle Easts conflicts, as well as any related political or economic response, counter responses or otherwise, financial services sector instability, a reduction in business confidence and activity, financial market volatility, unexpected changes in tax law or policy, and other factors. Such events can adversely affect our operations or the economy as a whole and may cause our customers to delay their decisions on spending for the services we provide and perpetuate significant changes in regional and global economic conditions and cycles. These events may also pose risks to our personnel and to physical facilities and operations, which could adversely affect our financial results.

Added

Changes in tax law could materially impact our business, results of operations and financial condition.

Added

Changes to U.S. federal, state, and local, and foreign tax laws that may be enacted in the future could impact the tax treatment of our business operations. Our effective tax rate could be adversely affected by several factors, many of which are outside of our control, including changes in the mix of earnings and losses in countries with differing statutory tax rates, changes in the valuation of deferred tax assets and liabilities, changes in tax laws, rates, treaties and regulations or the interpretation of the same, changes to the financial accounting rules for income taxes, the outcome of current and future tax audits, examinations or administrative appeals and certain non-deductible expenses. In addition, many jurisdictions, including the United States, are actively considering changes to existing tax laws or have proposed or enacted new laws, such as the recently enacted U.S. federal tax legislation commonly referred to as the One Big Beautiful Bill Act (OBBB Act), that could increase our tax obligations in countries where we do business or cause us to change the way we operate our business. We are currently evaluating the full impact of the OBBB Act on us. As of December 31, 2025, the OBBB Act has had no material income tax impact on our financial statements.

Added

In addition, the Organization for Economic Cooperation and Development has proposed imposing a 15% global minimum tax under the Pillar Two Model Rules (Pillar Two), and this proposal has been adopted or is being considered by a number of countries, which could impact our business if we expand internationally. However, on June 28, 2025, the G7 released a joint statement that it had reached an understanding with the United States for a side-by-side system based on certain accepted principles, including that U.S.-parented groups, such as ours, would be exempt from certain provisions of Pillar Two. Any of these developments or changes in U.S. federal, state or international tax laws or tax rulings could adversely affect our effective tax rate and our operating results. As of December 31, 2025, we are not yet subject to Pillar Two due to the level of gross receipts.

Reworded

Our common stock is currently listed on the NYSENasdaq Stock Market LLC (Nasdaq) and was previously listed on theNYSE and NYSE American LLC (formerly the NYSE MKT LLC). Over the past years,year, the market price of our common stock has experienced significant fluctuations. Between January 1, 2024,2025, and December 31, 2024,2025, the adjusted closing price on the NYSE for our common stock ranged between $3.62$6.80 and $9.22.$24.84. The price of our common stock may continue to be volatile as a result of several factors, some of which are beyond our control. These factors include, but are not limited to, the following:

Reworded

In addition, we believe there has been and may continue to be substantial trading in derivatives of our stock, including short selling activity or related similar activities, which are beyond our our control, and which may be beyond the full control of the SEC and Financial Institutions Regulatory Authority (“FINRA”). While the SEC and FINRA rules prohibit some forms of short selling and other activities that may result in stock price manipulation, manipulation, such activity may nonetheless occur without detection or enforcement. We have held conversations with regulators concerning trading activity in our stock; however, there can be no assurance that should there be any illegal manipulation in the trading of our stock, it will be detected, prosecuted, or successfully eradicated. Significant short sellingshort-selling market manipulation could cause our stock trading price to decline, to become more volatile, or both. For more information regarding trading in our common stock and listing on the NYSE,Nasdaq, see additional risk factors included elsewhere in this Annual Report on Form 10-K.

Reworded

In addition, an entity that, among other things, is or holds itself out as being engaged primarily, or proposes to engage primarily, in the business of investing, reinvesting, owning, trading, or holding certain types of securities would be deemed an Investment Company under the Investment Company Act of 1940 (the “1940 Act”). If we do not manage our investments and business in a manner that meets the requirements for an exemption under the 1940 Act, we may be deemed to be an investment company under the 1940 Act and subject to additional limitations on operating our business including limitations on the issuance of securities, which may make it difficult for us to raise capital.

Management's Discussion & Analysis (MD&A) (10-K Item 7)

16new paragraphs
7removed paragraphs
7reworded paragraphs
2,683 → 3,029words in section

Largest changes (selected automatically by length and topic keywords; quoted verbatim, no commentary)

Removed text topics: artificial intelligence, ai, labor
“We continue to augment our product strategy to provide secure AI to the marketplace. …”
see in full comparison
New text topics: fine, labor
“We are developing a Center for Advanced Software and Hardware Integration at our Farmington, Utah facility, that incorporates artificial intelligence (AI) and digital twin technologies alongside our Software-Defined Networks (SDN) capabilities. This facility is intended to support development and integration of secure, adaptive software solutions. …”
see in full comparison
New text topics: export control, regulation
“We also support international sales of our commercial products in compliance with applicable U.S. export control laws and regulations, including the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). Our compliance processes are designed to ensure that international transactions adhere to export control requirements while supporting authorized global customers.”
see in full comparison
New text topics: export control
“We hold a Multiple Award Schedule (MAS), enabling streamlined procurement of our products and services by federal, state, and local government customers. We have also obtained Department of Defense Joint Certification Program (DD Form 2345) certifications for our facilities in Zephyr Cove, Nevada, and Farmington, Utah, which permit access to certain unclassified technical data subject to export controls. These certifications support our ability to engage with government and defense customers while maintaining compliance with applicable handling and security requirements.”
see in full comparison
Removed text topics: fine
“Our employees include the core development team behind our inventions, technology, and software. Some members of this team have worked together for over twenty years and were on the same team that invented and developed this technology while working at Leidos, Inc., or Leidos, (f/k/a Science Applications International Corporation, or SAIC). The team has continued its research and development work to refine our unique network security technology and make it more secure and easy to deploy.”
see in full comparison
New text topics: fine
“Our employees include the core development team behind our inventions, technology, and software. Some members of this team have worked together for over twenty years and were on the same team that invented and developed this technology while working at Leidos, Inc. The team has continued its research and development work to refine our unique network security technology and make it more secure and easy to deploy.”
see in full comparison
Full comparison: every changed paragraph (30)

Green = added, red = removed. Unchanged paragraphs, 4 paragraphs where only numbers/dates changed, and tables are not shown. Read the complete text in the original filing.

Added

VirnetX Holding Corporation (“Company”, “we”, “us”, or “our”) is an Internet security software and technology company with patented cybersecurity solutions that are designed to ensure resilient, secure communications across any network or device.

Removed

We are an Internet security software and technology company with patented technology for Zero Trust Network Access (“ZTNA”) based secure network communications. VirnetX’s software and technology solutions, including its Secure Domain Name Registry and Technology, VirnetX One™, War Room™, and VirnetX Matrix™ are designed to be device and location-independent, and enable a secure real-time communication environment for all types of enterprise applications, services, and critical infrastructures. Our technology generates secure connections on a “single-click” basis, significantly simplifying the deployment of secure real-time communication solutions by eliminating the need for end-users to enter any encryption information.

Reworded

Our productflagship portfolioplatform, includesVirnetX sophisticatedOne™, technologies,is productsbuilt on Zero Trust Network Access (ZTNA) principles and servicesextends thatour arepatented availableSecure forDomain saleName worldwide.System Our(SDNS) next-generation,technology to establish end-to-end encrypted communications on demand, regardless of user location or endpoint. VirnetX One™ platformoperates builds upon our patented Secure Domain Name Registry and Technology to further enhance the security and efficiency of our patented secure communication links. VirnetX One™ isas a security-as-a-service platform thatand protectsmay be deployed in cloud, on-premise, or hybrid enterprise environments. The platform is designed to protect applications, services, and infrastructure fromby cyber-attacks.providing Ouran platformadditional allowssecurity governmentlayer organizations,that businesses,integrates andwith otherexisting enterprises of all sizessystems to addreduce a “security umbrella” as an added layer on top of their existing infrastructureexposure to furtherevolving reducecyber riskthreats and bolster security against ever-growing cyberthreats toaffecting data, operating systems, other infrastructure productscomponents, and gateway security controllers.

Added

VirnetX Matrix™ leverages the VirnetX One™ platform to secure communications using encrypted, identity-based access controls, including in contested or high-risk environments. It is designed to protect internet-enabled enterprise applications, connected devices, and control systems, such as file servers, data backup systems, and VPN or firewall environments. VirnetX Matrix™ is intended to be deployed without requiring material changes to an enterprise’s existing infrastructure and provides centralized visibility and policy enforcement to address unauthorized access and evolving attack techniques.

Added

VirnetX War Room™, also built on the VirnetX One™ PLATFORM, provides secure collaboration and visualization capabilities designed to support sensitive, unclassified but secure communications. The platform enables controlled access to virtual meeting environments by validating user and device permissions prior to granting access. VirnetX War Room™ is intended for use cases where confidentiality and access control are critical, including government, law enforcement, legal, financial, and healthcare environments.

Added

Our products, including VirnetX One™, VirnetX Matrix™, and VirnetX War Room™, are designed to support U.S. Department of Defense (DoD), federal government, and commercial customers requiring real-time encrypted communications and network security. We believe our solutions are applicable across a range of public and private sector markets, including critical infrastructure, law enforcement, healthcare, financial services, legal services, energy, and related industries. We pursue sales opportunities nationwide and engage with universities and academic institutions to support research collaboration, workforce development, and technology transition initiatives.

Added

We also support international sales of our commercial products in compliance with applicable U.S. export control laws and regulations, including the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). Our compliance processes are designed to ensure that international transactions adhere to export control requirements while supporting authorized global customers.

Added

Our technology roadmap addresses the continued growth of Internet of Things (IoT) and edge computing environments. We are extending secure networking capabilities to resource-constrained devices through obfuscated and lightweight security mechanisms designed to protect communications without exposing underlying security processes. These efforts support secure identity, trust enforcement, and encrypted communications for distributed and edge-based systems.

Added

We are developing a federated, hybrid mesh network architecture designed with security as a foundational element. This approach incorporates dynamic trust evaluation, autonomous recovery, and distributed decision-making to enhance network resilience and adaptability. We believe this architecture aligns with broader industry trends toward decentralized and resilient network models.

Added

To support system design and evaluation, we employ Model-Based Systems Engineering (MBSE) and agent-based modeling methodologies. These approaches enable simulation and analysis of complex systems, including cyber-physical environments and adaptive networks, and support assessment of system behavior under evolving threat conditions.

Added

We have undertaken efforts to align certain services with the Department of Defense Digital Engineering (DE) strategy. These services are intended to support cybersecurity integration across system design, command and control, battle management, and sensor orchestration, and to enhance our MBSE and cyber threat assessment capabilities. Our Dynamic Trust Evaluation (DTE) methods are designed to enforce trust policies throughout system lifecycles, and our cyber threat intelligence and assessment services provide structured analysis of cyber risks and vulnerabilities.

Added

We intend to make available digital engineering, cyber MBSE, and cyber threat intelligence services to federal, state, and local government agencies, subject to applicable contracting requirements. These services include cybersecurity-focused system design support, advanced modeling of communication flows and threat boundaries, and structured cyber risk assessment methodologies.

Added

We are developing a Center for Advanced Software and Hardware Integration at our Farmington, Utah facility, that incorporates artificial intelligence (AI) and digital twin technologies alongside our Software-Defined Networks (SDN) capabilities. This facility is intended to support development and integration of secure, adaptive software solutions. We have entered into strategic relationships, including an investment in L2 Holdings, LLC (OmniTeq), an AI/Machine Learning (ML) solutions provider and cooperative agreements, including a Cooperative Research and Development Agreement (CRADA) with the Air Force Research Laboratory, Intelligence Systems Directorate (AFRL/RI). The CRADA focuses on cybersecurity and Zero Trust Network Access (ZTNA)-related technologies, extends through 2030, and supports collaboration in areas relevant to defense and intelligence operations.

Added

We hold a Multiple Award Schedule (MAS), enabling streamlined procurement of our products and services by federal, state, and local government customers. We have also obtained Department of Defense Joint Certification Program (DD Form 2345) certifications for our facilities in Zephyr Cove, Nevada, and Farmington, Utah, which permit access to certain unclassified technical data subject to export controls. These certifications support our ability to engage with government and defense customers while maintaining compliance with applicable handling and security requirements.

Added

Durning 2025, we provided subject matter and technical expertise as a subcontractor under a U.S. Department of Defense contract in support of activities directed by the Air Force Research Laboratory (“AFRL”). While there can be no assurance, we believe this engagement may represent a meaningful foothold in the national security sector and may provide pathways to follow-on activities and/or expansion into broader strategic programs.

Removed

Our War Room™ software product provides safe and secure video conferencing meeting environment where sensitive communications and data is invisible to those not authorized to view it. War Room™ validates permissions of all the users, and devices requesting access to any secure meeting room prior to granting access. We believe our War Room™ will be an attractive solution for government and law enforcement agencies as well as all professional sectors such as legal, financial, and medical where limiting access to confidential data is a critical requirement.

Removed

Our VirnetX Matrix™ product provides superior security for internet-enabled enterprise applications and their connected devices, and for control systems currently deployed by those enterprises (e.g., file servers, data back-up systems, VPN/firewalls). VirnetX Matrix™ provides a true “zero-trust” access protection, “single-click” ease of use, and is a highly-effective added layer of protection that is deployed simply, without the need for changes to an enterprise’s existing, in-place infrastructure. We believe VirnetX Matrix™ is an attractive solution for all businesses, cloud and on-premise application service providers, and original equipment manufacturers (“OEMs”), looking to improve visibility and management of their networks to mitigate morphing attacks on their networks and for real time access and control of their users.

Removed

We continue to augment our product strategy to provide secure AI to the marketplace. In addition to our investments with L2 Holdings, LLC (“OmniTeq”), an artificial intelligence and machine learning (AI/ML) solutions provider and OP Media, Inc, a dynamic software platform provider, we participated in a Cooperative Research and Development Agreement (CRADA) with the Air Force (AF) Research Laboratory Intelligence Systems Directorate (AFRL/RI) to facilitate collaboration on cybersecurity and Zero Trust technologies to support integrated surveillance and reconnaissance operations as well as AF and joint targeting processes. This CRADA continues through 2030 and allows VirnetX to apply for security clearances for its employees. We are also beginning to integrate AI/ML capabilities into VirnetX Matrix™ to enhance its zero-trust security, threat detection, and network resilience by enabling autonomous threat response, adaptive access control, and self-healing network architectures.

Removed

We have undertaken activities to commercialize our products and intellectual property in and outside the United States including VirnetX One™, War Room™, VirnetX Matrix™ and our Secured Domain Name Registry and Technology. We believe our product portfolio to secure devices and systems are suitable in areas such as national defense, local, state, Federal and foreign governments, critical infrastructure, law enforcement, healthcare, finance, legal, oil and gas, medical, and related support industries. We continue to actively pursue new sales opportunities in and outside of the United States.

Removed

Our employees include the core development team behind our inventions, technology, and software. Some members of this team have worked together for over twenty years and were on the same team that invented and developed this technology while working at Leidos, Inc., or Leidos, (f/k/a Science Applications International Corporation, or SAIC). The team has continued its research and development work to refine our unique network security technology and make it more secure and easy to deploy.

Reworded

Our portfolio of intellectual property portfolio is thea foundationcore component of our business model.business. We currently own U.S. and foreign patents/validations/patents, as well as pending applications. Our patent portfolioapplications, isthat are primarily focused ondirected to securing real-time communications over the Internet, Internet and related services,services. andThese ispatents used in allunderpin our technology and products,products. someCertain portions of whichthis portfolio were acquired by our principal operating subsidiary, VirnetX, Inc., from LeidosLeidos, Inc. in 2006.

Added

Our employees include the core development team behind our inventions, technology, and software. Some members of this team have worked together for over twenty years and were on the same team that invented and developed this technology while working at Leidos, Inc. The team has continued its research and development work to refine our unique network security technology and make it more secure and easy to deploy.

Reworded

We have a facility lease in California, used for corporate, promotionalpromotional, and marketing purposes. The lease expires in 2035.

Reworded

Investments classified as available-for-sale are recorded at fair market value. Unrealized gains and losses are reported as other comprehensive income. Realized gains and losses are recorded in income in the period they are realized using specific identification of each security’s cost basis. We invest our excess cash primarily in highly liquid debt instruments including corporate, government and federal agency securities, with contractual maturities less than two years. By policy, we limit the amount of credit exposure to any one issuer.

Reworded

We have elected the investment measurement alternative for other investments without readily determinable fair values. During 2023, we invested $2,000 in L2 Holdings LLCOmniTeq and $500 in OP Media Inc. These investments are carried at our initial cost less any impairment because we do not have the ability to exercise significant influence over operating and financial matters. For these investments, we adjust the carrying value for any purchases or sales of our ownership interests. Periodically, we evaluate these investments for impairment. If we identify an impairment, we reduce the carrying value for the impairment loss with a charge to earnings.operating Weexpenses. haveEffective notSeptember 30, 2025 we identified identified anyan impairment in our investment in OP Media Inc., and as ofa Decemberresult, 31,we 2024.recognized an impairment loss totaling $500.

Added

Revenue generated in 2025 was $162, compared to $5 in 2024. During 2025, we provided subject matter and technical expertise as a subcontractor under a U.S. Department of Defense contract is support of activities directed by AFRL.

Removed

Revenue generated in 2024 was $5, compared to $7 in 2023.

Reworded

Interest and other income in 20242025 was $2,225$1,213 compared to $3,495$2,225 in 2023,2024, due to a decrease in investments.

Added

As of December 31, 2025, our cash and cash equivalents totaled $15,548 and our short-term investments totaled $5,979 compared to $23,296 and $14,786, respectively, as of December 31, 2024.

Reworded

As of December 31, 2024, our cash and cash equivalents totaled $23,296 and our short-term investments totaled $14,786 compared to $26,289 and $27,258, respectively, as of December 31, 2023. We expect that our cash and cash equivalents and short-term investments as of December 31, 2024,2025, will be sufficient to fund our current level of selling, general and administration costs and provide related working capital for the foreseeable future. Over the longer term, we expect to derive the majority of our future revenue from collaborating with others to integrate our family of cybersecurity products and services into their solutions and to resell them to their current and future customers as well as from license fees and royalties associated with our patent portfolio, technology, software and secure domain name registry and product sales.registry.

What changed in the latest 10-Q

Comparing 10-Q filed 2026-08-14 (period ending 2026-06-30) with 10-Q filed 2026-05-15 (period ending 2026-03-31).

Risk Factors (10-Q Part II, Item 1A)

0new paragraphs
0removed paragraphs
8reworded paragraphs
7,614 → 7,609words in section

Largest changes (selected automatically by length and topic keywords; quoted verbatim, no commentary)

Reworded

Paragraph as it now reads, with added and removed wording marked:

TheBased on the Company’s current levelrate of operating expenditures,expenditures if continuedand without additionalgiving sourceseffect ofto revenueany future financing or financing, would exhaustrevenues, existing liquid resources inare projected to be insufficient to sustain the current second quarterlevel of 2027,operations afor period of less than twelve months from the date of issuance of thethese financial statements included in this Report on Form 10-Q.statements. Under U.S. GAAP, this condition requires disclosure of substantial doubt about the Company’s ability to continue as a going concern, as set forth forth in the Notes to our condensed consolidated financial statements. This disclosure reflects the application of prescribed accounting standards and is not intended to imply any change in the Company’s expectations regarding its business, strategy or outlook.
see in full comparison
Reworded

Paragraph as it now reads, with added and removed wording marked:

We had a net loss of $4.4$8.9 million for the quartersix months ended MarchJune 31,30, 2026, and a net loss of $18.2 million for the year ended December 31, 2025. As of MarchJune 31,30, 2026, we had an accumulated deficit of $227.2$231.8 million.
see in full comparison
Reworded

Paragraph as it now reads, with added and removed wording marked:

The exercise of our outstanding vested stock options and the vesting of RSUs dilutes the ownership interests of our existing stockholders. As of MarchJune 31,30, 2026, we had 697,758685,339 outstanding RSUs and options to purchase shares of common stock representing approximately 18%17% of our total shares outstanding of which 227,490218,337 were vested. To the extent restricted stock is awarded, outstanding stock options are exercised, and RSUs vest, existing stockholders’ percentage voting interests will decline. Also, the number of shares eligible for resale in the public market will increase and such increase may have a negative effect on the value or market trading price of our common stock.
see in full comparison
Full comparison: every changed paragraph (8)

Green = added, red = removed. Unchanged paragraphs and tables are not shown. Read the complete text in the original filing.

Reworded

TheBased on the Company’s current levelrate of operating expenditures,expenditures if continuedand without additionalgiving sourceseffect ofto revenueany future financing or financing, would exhaustrevenues, existing liquid resources inare projected to be insufficient to sustain the current second quarterlevel of 2027,operations afor period of less than twelve months from the date of issuance of thethese financial statements included in this Report on Form 10-Q.statements. Under U.S. GAAP, this condition requires disclosure of substantial doubt about the Company’s ability to continue as a going concern, as set forth forth in the Notes to our condensed consolidated financial statements. This disclosure reflects the application of prescribed accounting standards and is not intended to imply any change in the Company’s expectations regarding its business, strategy or outlook.

Reworded

We had a net loss of $4.4$8.9 million for the quartersix months ended MarchJune 31,30, 2026, and a net loss of $18.2 million for the year ended December 31, 2025. As of MarchJune 31,30, 2026, we had an accumulated deficit of $227.2$231.8 million.

Reworded

The exercise of our outstanding vested stock options and the vesting of RSUs dilutes the ownership interests of our existing stockholders. As of MarchJune 31,30, 2026, we had 697,758685,339 outstanding RSUs and options to purchase shares of common stock representing approximately 18%17% of our total shares outstanding of which 227,490218,337 were vested. To the extent restricted stock is awarded, outstanding stock options are exercised, and RSUs vest, existing stockholders’ percentage voting interests will decline. Also, the number of shares eligible for resale in the public market will increase and such increase may have a negative effect on the value or market trading price of our common stock.

Reworded

As of MarchJune 31,30, 2026, our executive officers and directors beneficially owned approximately 16% of our outstanding common stock. Because of their beneficial ownership interest, our officers and directors could significantly influence stockholder actions. This ability to exercise significant influence could prevent or significantly delay another company from acquiring or merging with us.

Reworded

To the extent we are unable to secure additional revenue over the next several months, we will need to raise additional capital in the near term. Based on our current level of operating expenditures, we project that our existing cash, cash equivalents and short-term investments will be insufficient to fund the current level of operations, and we have therefore concluded that the conditions for a going concern disclosure under U.S. GAAP are present, as described in the notes to our consolidated financial statements. Our ability to obtain additional capital, if and when required, will depend on our business plans, investor demand, our operating performance, the condition of the capital markets, the terms of our current contractual obligations and other factors.

Reworded

Changes to U.S. federal, state, and local, and foreign tax laws that may be enacted in the future could impact the tax treatment of our business operations. Our effective tax rate could be adversely affected by several factors, many of which are outside of our control, including changes in the mix of earnings and losses in countries with differing statutory tax rates, changes in the valuation of deferred tax assets and liabilities, changes in tax laws, rates, treaties and regulations or the interpretation of the same, changes to the financial accounting rules for income taxes, the outcome of current and future tax audits, examinations or administrative appeals and certain non-deductible expenses. In addition, many jurisdictions, including the United States, are actively considering changes to existing tax laws or have proposed or enacted new laws, such as the recently enacted U.S. federal tax legislation commonly referred to as the One Big Beautiful Bill Act (OBBB Act), that could increase our tax obligations in countries where we do business or cause us to change the way we operate our business. We are currently evaluating the full impact of the OBBB Act on us. As of MarchJune 31,30, 2026, the OBBB Act has had no material income tax impact on our financial statements.

Reworded

In addition, the Organization for Economic Cooperation and Development has proposed imposing a 15% global minimum tax under the Pillar Two Model Rules (Pillar Two), and this proposal has been adopted or is being considered by a number of countries, which could impact our business if we expand internationally. However, on June 28, 2025, the G7 released a joint statement that it had reached an understanding with the United States for a side-by-side system based on certain accepted principles, including that U.S.-parented groups, such as ours, would be exempt from certain provisions of Pillar Two. Any of these developments or changes in U.S. federal, state or international tax laws or tax rulings could adversely affect our effective tax rate and our operating results. As of MarchJune 31,30, 2026, we are not yet subject to Pillar Two due to the level of gross receipts.

Reworded

Our common stock is currently listed on the Nasdaq Stock Market LLC (Nasdaq) and was previously listed on NYSE and NYSE American LLC (formerly the NYSE MKT LLC). Over the past year, the market price of our common stock has experienced significant fluctuations. Between AprilJuly 1, 2025, and MarchJune 31,30, 2026, the adjusted closing price for our common stock ranged between $7.50$11.37 and $24.84. The price of our common stock may continue to be volatile as a result of several factors, some of which are beyond our control. These factors include, but are not limited to, the following:

Management's Discussion & Analysis (MD&A) (10-Q Part I, Item 2)

3new paragraphs
1removed paragraphs
9reworded paragraphs
1,450 → 1,696words in section

Largest changes (selected automatically by length and topic keywords; quoted verbatim, no commentary)

New text
“VirnetX iSCOUT (IoT System for Connected Object Understanding and Telemetry) leverages a common, secure IoT and data infrastructure to fuse sensor, geospatial, and agency data into a unified operating picture, including in disaster response and smart city environments. …”
see in full comparison
New text
“As of June 30, 2026, our cash and cash equivalents totaled approximately $13,090 and our short-term investments totaled approximately $799, compared to cash and cash equivalents of approximately $15,548 and short-term investments of approximately $5,979 at December 31, 2025, respectively. Working capital was $11,847 at June 30, 2026.”
see in full comparison
Reworded

Paragraph as it now reads, with added and removed wording marked:

Our research and development expenses remaineddecreased steadyslightly betweenin 2026 andcompared 2025to 2025, totaling $1,162$1,126 and $1,259$1,215 for the three months ended MarchJune 31,30, 2026 and 2025, respectively.and totaling $2,288 and $2,474 for the six months ended June 30, 2026 and 2025. The decrease was related to compensation.
see in full comparison
New text
“On June 2, 2026, the SEC declared our shelf registration statement of Form S-3 effective (File No. 333-295960). The S-3 covers the offer and sale up to $20 million in securities in one or more offerings, in amounts, at prices and on terms determined at the time of the offering.”
see in full comparison
Reworded

Paragraph as it now reads, with added and removed wording marked:

Our selling, general and administrative expenses increased from$749 $2,788and to$1,308 $3,346 forin the three and six months ended MarchJune 31,30, 2026,2026 compared to 2025. The variance was primarily related to compensationincreases expenseof $388 in legal expenses, $362 in equity compensation, and corporate$395 travel.in travel expense.
see in full comparison
Reworded

Paragraph as it now reads, with added and removed wording marked:

We intend to make available our digital engineering, cyber MBSE, and cyber threat intelligence services to federal, state, and local government agencies, subject to applicable contracting requirements. We hold a Multiple Award Schedule (MAS) and obtained DoD Joint Certification Program (DD Form 2345) certifications for our facilities in Zephyr Cove, Nevada, and Farmington, Utah, which permit access to certain unclassified technical data subject to export controls. These certifications streamline procurement of our products and services by federal, state, and local government agencies and support our ability to engage with government and defense customers while maintaining compliance with applicable handling and security requirements.
see in full comparison
Full comparison: every changed paragraph (13)

Green = added, red = removed. Unchanged paragraphs and tables are not shown. Read the complete text in the original filing.

Reworded

VirnetX War Room™ is also built on the VirnetX One™ platform, provides secure collaboration and visualization capabilities designed to support sensitive, unclassified but secure communications. The platform enables controlled access to virtual meeting environments by validating user and device permissions prior to granting access. VirnetX War Room™ is intended for use cases where confidentiality and access control are critical, including government, law enforcement, legal, financial, and healthcare environments.

Added

VirnetX iSCOUT (IoT System for Connected Object Understanding and Telemetry) leverages a common, secure IoT and data infrastructure to fuse sensor, geospatial, and agency data into a unified operating picture, including in disaster response and smart city environments. It is designed to support mission-specific applications that can be customized for a range of markets, with two initial implementations currently in development: a Humanitarian Assistance Disaster Relief–Emergency Response (HADR-ER) capability that provides federal, state, and local partners with a real-time operating picture for national emergency management, and a smart city solution for international markets, including Japan, tailored to urban resilience, mobility, and critical infrastructure monitoring in dense metropolitan environments. VirnetX iSCOUT is intended to be deployed as a shared, exportable technology stack, with each application configured for its distinct mission, and we may pursue additional customized applications for other markets in the future.

Reworded

We intend to make available our digital engineering, cyber MBSE, and cyber threat intelligence services to federal, state, and local government agencies, subject to applicable contracting requirements. We hold a Multiple Award Schedule (MAS) and obtained DoD Joint Certification Program (DD Form 2345) certifications for our facilities in Zephyr Cove, Nevada, and Farmington, Utah, which permit access to certain unclassified technical data subject to export controls. These certifications streamline procurement of our products and services by federal, state, and local government agencies and support our ability to engage with government and defense customers while maintaining compliance with applicable handling and security requirements.

Reworded

Three and Six Months Ended MarchJune 31,30, 2026

Reworded

Compared with the Three and Six Months Ended MarchJune 31,30, 2025

Reworded

We recognized norevenue revenue$48 in the three months and six months ended MarchJune 31,30, 20262025 and 2025.no revenue during the same periods in 2026.

Reworded

Our research and development expenses remaineddecreased steadyslightly betweenin 2026 andcompared 2025to 2025, totaling $1,162$1,126 and $1,259$1,215 for the three months ended MarchJune 31,30, 2026 and 2025, respectively.and totaling $2,288 and $2,474 for the six months ended June 30, 2026 and 2025. The decrease was related to compensation.

Reworded

Our selling, general and administrative expenses increased from$749 $2,788and to$1,308 $3,346 forin the three and six months ended MarchJune 31,30, 2026,2026 compared to 2025. The variance was primarily related to compensationincreases expenseof $388 in legal expenses, $362 in equity compensation, and corporate$395 travel.in travel expense.

Added

As of June 30, 2026, our cash and cash equivalents totaled approximately $13,090 and our short-term investments totaled approximately $799, compared to cash and cash equivalents of approximately $15,548 and short-term investments of approximately $5,979 at December 31, 2025, respectively. Working capital was $11,847 at June 30, 2026.

Removed

As of March 31, 2026, the Company held approximately $17.2 million in cash, cash equivalents and short-term investments.

Reworded

Based on the Company’s current rate of operating expenditures and without giving effect to any future financing or additional revenue, existing liquid resources are projected to be insufficient to sustain the current level of operations through May 2027, a period of less thanfor twelve months from the date of issuance of these financial statements. This condition triggers the going concern disclosure requirements under U.S. GAAP and as required, is described in notes to our condensed consolidated financial statements. Management intends to continue pursuit of cash generation via revenue sources and financing.

Added

On June 2, 2026, the SEC declared our shelf registration statement of Form S-3 effective (File No. 333-295960). The S-3 covers the offer and sale up to $20 million in securities in one or more offerings, in amounts, at prices and on terms determined at the time of the offering.

Reworded

Our effective tax rate is 0% for income tax for the three and six months ended MarchJune 31,30, 2026 and 2025, and we expect our effective tax rate for the full year will be 0%. Our effective tax rate is less than the 21% statutory tax rate primarily due to our valuation allowance. Based on the weight of available evidence, including net cumulative losses and expected future losses, we have determined it is more likely than not that our U.S. federal and state deferred tax assets will not be realized and therefore we have provided a full valuation allowance on the U.S. federal and state net deferred tax assets.

VHC insider buying and selling (Form 4)

Since 2026-04-11, insiders reported open-market purchases in 0 Form 4 filings and open-market sales in 4 filings (3 insiders, 7 trade dates, 43,500 shares, about $489.1K; 4 of these filings say the sales were made under a Rule 10b5-1 trading plan). Net open-market shares: -43,500 (purchases minus sales); net value about -$489.1K.Totals add up every open-market (code P and S) line in those filings, using the prices reported in the filings. Awards, option exercises, tax withholding and gifts are listed below but not counted.

Trade dateInsiderTransactionSharesPriceValueOwned afterFiling
2026-09-30Angelo Michael F
Director
Open-market sale
10b5-1 plan
1,000$10.26 $10.3K28,209 SEC
2026-09-14Larsen Kendall
Director, President & CEO, 10% owner
Open-market sale
10b5-1 plan
4,425$11.17 $49.4K339,633 SEC
2026-09-11Larsen Kendall
Director, President & CEO, 10% owner
Open-market sale
10b5-1 plan
8,000$11.37 $91.0K344,058 SEC
2026-09-10Larsen Kendall
Director, President & CEO, 10% owner
Open-market sale
10b5-1 plan
8,000$11.48 $91.8K352,058 SEC
2026-09-02Larsen Kendall
Director, President & CEO, 10% owner
Open-market sale
10b5-1 plan
4,057$11.43 $46.4K360,576 SEC
2026-09-02Larsen Kendall
Director, President & CEO, 10% owner
Open-market sale
10b5-1 plan
518$12.13 $6.3K360,058 SEC
2026-09-01Larsen Kendall
Director, President & CEO, 10% owner
Open-market sale
10b5-1 plan
5,000$11.00 $55.0K364,633 SEC
2026-09-01Feiner Gary
Director
Open-market sale
10b5-1 plan
3,750$11.00 $41.2K16,874 SEC
2026-08-31Larsen Kendall
Director, President & CEO, 10% owner
Open-market sale
10b5-1 plan
5,000$11.17 $55.9K369,633 SEC
2026-08-31Feiner Gary
Director
Open-market sale
10b5-1 plan
3,749$11.17 $41.9K20,625 SEC
2026-08-31Feiner Gary
Director
Open-market sale
10b5-1 plan
1$12.03 $1220,624 SEC
2026-07-06Allanson Katherine
Chief Financial Officer
Shares withheld for tax 100$11.95 $1.2K31,205 SEC
2026-06-11O'brien Thomas M
Director
Grant/award 7,500— —35,457 SEC
2026-06-11Angelo Michael F
Director
Grant/award 7,500— —29,209 SEC
2026-06-11Chow Heidy Kingwan
Director
Grant/award 7,500— —37,500 SEC
2026-06-11Feiner Gary
Director
Grant/award 7,500— —24,374 SEC

Well-known investors holding VHC (13F)

None of the 59 investors we track reported a position in their latest 13F.

Coming soon: email alerts when VHC files, watchlists and downloadable comparisons.