PublicCVE

CVE-2026-50751

CRITICAL9.3Auth bypass
CISA KEVRansomwarePublic PoCHigh EPSS

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CVSS breakdown

CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None

Affected products

Exploits & proofs of concept

Updated 5m ago · 8 sources