Back

HIGH

Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1

Published Jun 8, 2026

Description

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner checkpoint
Published Jun 8, 2026
Updated Jun 10, 2026
Reserved Jun 7, 2026
CISA Vulnrichment
Updated Jun 9, 2026
NVD
Status Awaiting Analysis
Modified Jul 23, 2026
Red Hat
Severity n/a
Public date n/a