
@BleepinComputer In order to get beyond MFA and steal session cookies, the exploit combines CVE-2026-40891 with a second flaw (CVE-2026-40892). This enables hackers to take over active VPN sessions without the need for passwords. Patch 6.2.5 or 6.3.3 right away, and terminate any open sessions.
Post summary
The post alerts users to CVE‑2026‑40891 and CVE‑2026‑40892, advising immediate patching of versions 6.2.5 or 6.3.3 to prevent potential VPN session takeover scenarios.


