Back to overview

CVE-2026-50751

CRITICAL KEV CISA Exploitation: ACTIVE Ransomware noto
9.3
CVSS 3.1
Description
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Metadata

CVE ID
CVE-2026-50751
State
PUBLISHED
Assigner
checkpoint
Reserved
2026-06-07 09:42 UTC
Published
2026-06-08 11:07 UTC
Last updated
2026-06-10 13:37 UTC
Primary CWE
CWE-287
CWE-287: Improper Authentication.
Vendor / Product
checkpoint / Quantum Security Gateway
Sources
cve.org  ·  NVD

Severity & Metrics

9.3 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Check Point Security Gateway Improper Authentication Vulnerability
Vendor
Check Point
Product
Security Gateway
Added to KEV
2026-06-08
Due date
2026-06-11
Ransomware
Known use
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA description
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Affected products (2)
VendorProductPlatformVersions
checkpoint Quantum Security Gateway R82.10 with Jumbo Hotfix Take 19 or below, R82 with Jumbo Hotfix Take 103 or below, R81.20 with Jumbo Hotfix Take 141 or below, R81.10, R81, and R80.40
checkpoint Spark Firewalls R80.20.X, R81.10.X, and R82.00.X
Weakness (CWE)
CWESourceDescription
CWE-287 cna CWE-287: Improper Authentication.
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.3 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Back to overview