SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2026-50751

Check Point Security Gateway Improper Authentication Vulnerability

KEVCRITICAL 9.3EPSS 83.8%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 11 June 2026). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CVSS 3.1
9.3 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
EPSS
83.77% probability · 100th percentile
CISA KEV
Listed 8 June 2026 · due 11 June 2026 · used in ransomware campaigns
Weakness
CWE-287
Affected
checkpoint/gaia os · checkpoint/gaia embedded
Source
cve@checkpoint.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ ; https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM. ; https://nvd.nist.gov/vuln/detail/CVE-2026-50751

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.