
@BleepinComputer In order to get beyond MFA and steal session cookies, the exploit combines CVE-2026-40891 with a second flaw (CVE-2026-40892). This enables hackers to take over active VPN sessions without the need for passwords. Patch 6.2.5 or 6.3.3 right away, and terminate any open sessions.
Post summary
The post warns that CVE-2026-40891 and CVE-2026-40892 can be combined to bypass MFA and hijack VPN sessions, urging immediate application of patches 6.2.5 or 6.3.3.


