PT-2026-47276 · Check Point · Check Point Vpn+1
CVE-2026-50751
·
Published
2026-06-08
·
Updated
2026-07-24
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Check Point Remote Access VPN (affected versions not specified)
Check Point Mobile Access (affected versions not specified)
Check Point Spark firewalls (affected versions not specified)
Description
An authentication bypass exists in the certificate validation process of the deprecated IKEv1 key exchange. This logic flow weakness allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid password, granting direct access to the corporate network. The issue has been exploited in the wild since May 7th, with a few dozen organizations targeted globally, including at least one confirmed intrusion by a Qilin ransomware affiliate.
Recommendations
Apply the hotfix provided by the vendor.
Disable IKEv1.
Enforce machine certificate authentication on the gateway.
Fix
RCE
LPE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Check Point Gaia
Check Point Vpn