CVE-2026-50751
CRITICAL
CVSS: 9.3
EPSS: 83.8%
VulnCheck KEV
Weaponized
CWE-287
T1078
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Published: 2026-06-08