CVE-2026-50752

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.

  • Published Jun 8, 2026
  • CVSS 7.4 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-50752 at the National Vulnerability Database