CVE-2020-16088: OpenBSD

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

iked in OpenIKED, as used in OpenBSD through 6.7, allows authentication bypass because ca.c has the wrong logic for checking whether a public key matches.

Affected products

  • OpenBSD OpenBSD: up to and including 6.7

Published 2020-07-28. Last modified 2026-06-17.