CVE-2026-50751
Check Point Security Gateway Improper Authentication Vulnerability
CVSS
9.3
Critical
EPSS
83.8%
p100
KEV
YES
Jun 8, 2026
Exploit Today
80
0-100
Published: Jun 8, 2026 · Last modified: Aug 4, 2026 · CWE-287
Product
Check Point / Security Gateway
Vulnerability
Check Point Security Gateway Improper Authentication Vulnerability
Added to KEV
Jun 8, 2026
Remediate by
Jun 11, 2026
Known ransomware use
Yes
Summary description
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes
https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ ; https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM. ; https://nvd.nist.gov/vuln/detail/CVE-2026-50751
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
- support.checkpoint.comhttps://support.checkpoint.com/results/sk/sk185033
- blog.checkpoint.comhttps://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50751