CVE-2026-50751Check Point Security Gateway Improper Authentication Vulnerability
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
View on NVDAnalysis
Esta vulnerabilidad crítica en Check Point Security Gateway permite a atacantes remotos no autenticados evadir la validación de certificados y conectarse a la VPN sin una contraseña válida. El fallo está siendo explotado activamente en el entorno real, comprometiendo directamente el acceso perimetral a la infraestructura interna de servidores y servicios. Se recomienda actualizar inmediatamente los gateways afectados que todavía utilicen el intercambio de llaves IKEv1.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NCWE-287CISA KEV
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
EPSS
Affects
checkpoint:gaia_oscheckpoint:gaia_embeddedcheckpoint:quantum_spark_1530checkpoint:quantum_spark_1550checkpoint:quantum_spark_1570checkpoint:quantum_spark_1570rcheckpoint:quantum_spark_1590checkpoint:quantum_spark_1595rcheckpoint:quantum_spark_1600checkpoint:quantum_spark_1800checkpoint:quantum_spark_1900checkpoint:quantum_spark_2000checkpoint:quantum_spark_1535checkpoint:quantum_spark_1555checkpoint:quantum_spark_1575checkpoint:quantum_spark_1575rcheckpoint:quantum_spark_2530checkpoint:quantum_spark_2550checkpoint:quantum_spark_2560checkpoint:quantum_spark_2570checkpoint:quantum_spark_2580checkpoint:quantum_spark_2590Technical description
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.