Back

CRITICAL KEV Used in ransomware campaigns

User Authentication Bypass in VPN Remote Access and Mobile Access

Published Jun 8, 2026 ·Due Jun 11, 2026

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner checkpoint
Published Jun 8, 2026
Updated Aug 4, 2026
Reserved Jun 7, 2026
CISA Vulnrichment
Updated Jun 9, 2026
NVD
Status Analyzed
Modified Aug 4, 2026
Red Hat
Severity n/a
Public date n/a