PT-2026-47276 · Check Point · Check Point Vpn
Published
2026-06-08
·
Updated
2026-06-09
·
CVE-2026-50751
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Check Point Security Gateway (affected versions not specified)
Description
A logic flow weakness in certificate validation for Remote Access and Mobile Access deployments using the deprecated IKEv1 key exchange protocol allows an unauthenticated remote attacker to bypass user authentication. This flaw enables the establishment of a remote access VPN connection without a valid user password, granting access to secure networks. This issue has been exploited in the wild to deploy ransomware linked to the Qilin gang.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Check Point Vpn