CVE-2026-50751
Check Point Security Gateway Improper Authentication Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 11 June 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
- CVSS 3.1
- 9.3 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
- EPSS
- 83.77% probability · 100th percentile
- CISA KEV
- Listed 8 June 2026 · due 11 June 2026 · used in ransomware campaigns
- Weakness
- CWE-287
- Affected
- checkpoint/gaia os · checkpoint/gaia embedded
- Source
- cve@checkpoint.com
CISA notes
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ ; https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM. ; https://nvd.nist.gov/vuln/detail/CVE-2026-50751
References
- https://support.checkpoint.com/results/sk/sk185033Mitigation, Patch, Vendor Advisory
- https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50751US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.