Improper Certificate Validation in Gaia - CVE-2026-85102
Published: September 10, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper validation of certificate data in the Remote Access and Site-to-Site VPN functionality when negotiating VPN connections. A remote attacker can send specially crafted certificate data during VPN negotiation to execute arbitrary code.