Skip to content
Actively exploitedCVSS 9.3 · CRITICAL

CVE-2026-50751Check Point Security Gateway Improper Authentication Vulnerability

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

View on NVD

Analysis

Esta vulnerabilidad crítica en Check Point Security Gateway permite a atacantes remotos no autenticados evadir la validación de certificados y conectarse a la VPN sin una contraseña válida. El fallo está siendo explotado activamente en el entorno real, comprometiendo directamente el acceso perimetral a la infraestructura interna de servidores y servicios. Se recomienda actualizar inmediatamente los gateways afectados que todavía utilicen el intercambio de llaves IKEv1.

Relevant roles

CyberSecurityCloudLinuxBackend

Severity

Score: 9.3(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: LOW
A: NONE
Weakness (CWE): CWE-287

CISA KEV

Added to KEV: 2026-06-08
Federal patch deadline: 2026-06-11
Known ransomware use: Known
Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

EPSS

Probability of exploitation (next 30 days): 0.8255 (82.6%)
Percentile: 99.6%
EPSS: 2026-08-03

Affects

checkpoint:gaia_oscheckpoint:gaia_embeddedcheckpoint:quantum_spark_1530checkpoint:quantum_spark_1550checkpoint:quantum_spark_1570checkpoint:quantum_spark_1570rcheckpoint:quantum_spark_1590checkpoint:quantum_spark_1595rcheckpoint:quantum_spark_1600checkpoint:quantum_spark_1800checkpoint:quantum_spark_1900checkpoint:quantum_spark_2000checkpoint:quantum_spark_1535checkpoint:quantum_spark_1555checkpoint:quantum_spark_1575checkpoint:quantum_spark_1575rcheckpoint:quantum_spark_2530checkpoint:quantum_spark_2550checkpoint:quantum_spark_2560checkpoint:quantum_spark_2570checkpoint:quantum_spark_2580checkpoint:quantum_spark_2590

Technical description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Published: 6/8/2026, 12:16:32 PM
Last modified: 8/4/2026, 5:16:39 AM

References

HomeEventsBlogResourcesCoursesTeam