PT-2026-47276 · Check Point · Check Point Vpn+1

CVE-2026-50751

·

Published

2026-06-08

·

Updated

2026-07-24

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Check Point Remote Access VPN (affected versions not specified) Check Point Mobile Access (affected versions not specified) Check Point Spark firewalls (affected versions not specified)
Description An authentication bypass exists in the certificate validation process of the deprecated IKEv1 key exchange. This logic flow weakness allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid password, granting direct access to the corporate network. The issue has been exploited in the wild since May 7th, with a few dozen organizations targeted globally, including at least one confirmed intrusion by a Qilin ransomware affiliate.
Recommendations Apply the hotfix provided by the vendor. Disable IKEv1. Enforce machine certificate authentication on the gateway.

Fix

RCE

LPE

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07962
CVE-2026-50751

Affected Products

Check Point Gaia
Check Point Vpn