CVE-2026-50751
Confirmed PUBLISHEDUser Authentication Bypass in VPN Remote Access and Mobile Access
6 hours faster than CISA KEV
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
- CVE Published
- Jun 08, 2026
- Exploitation Reported
- Jun 08, 2026
- CVSS
- 9.3 Critical
- EPSS
- 70.1%
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| checkpoint |
Quantum Security Gateway
|
R82.10 with Jumbo Hotfix Take 19 or below |
Affected |
| checkpoint |
Quantum Security Gateway
|
R82 with Jumbo Hotfix Take 103 or below |
Affected |
| checkpoint |
Quantum Security Gateway
|
R81.20 with Jumbo Hotfix Take 141 or below |
Affected |
| checkpoint |
Quantum Security Gateway
|
R81.10, R81, and R80.40 |
Affected |
| checkpoint |
Spark Firewalls
|
R80.20.X, R81.10.X, and R82.00.X |
Affected |
CVE References
- support.checkpoint.com/results/sk/sk185033 support.checkpoint.com · CVE Record https://support.checkpoint.com/results/sk/sk185033
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Check Point Blog First | 2026-06-08 14:20 UTC |
| TheHackerNews | 2026-06-08 15:20 UTC |
| Rapid7 | 2026-06-08 19:20 UTC |
| CISA | 2026-06-08 20:00 UTC |
| All CISA Advisories | 2026-06-08 20:20 UTC |
| CVE | 2026-06-08 20:41 UTC |
Operational indicators for this CVE are listed on the Detection tab.
Indicators of Compromise (IoCs)
Operational indicators linked to exploitation of this CVE. IoCs age over time — especially IP addresses.
| Type | Indicator | First Seen | Last Seen | Age | Source |
|---|---|---|---|---|---|
| IP |
45.77.149.152
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 2 months ago | Source |
| IP |
209.182.225.136
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 2 months ago | Source |
| IP |
38.60.157.139
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 2 months ago | Source |
| IP |
162.33.177.101
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 2 months ago | Source |
| IP |
45.76.26.42
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 2 months ago | Source |
| IP |
144.208.127.155
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 2 months ago | Source |
| IP |
38.54.88.201
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 2 months ago | Source |
| IP |
38.54.107.167
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 2 months ago | Source |
| IP |
66.42.99.200
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 2 months ago | Source |
Scanner Artifacts
Nuclei and Metasploit references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-50751.yaml | Jun 17, 2026 |
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Exploitation Status
Exploited in the wild
Recorded 2026-06-08 14:20:34 UTC · Check Point Blog
Used in qilin ransomware malware
Recorded 2026-06-08 15:14:29 UTC · Check Point Blog
Proof of concept available
Recorded 2026-06-10 15:32:15 UTC · GitHub
Weaknesses (CWE)
-
Improper Authentication
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-50751.yaml | Jun 17, 2026 |
Recent Mentions
Watchtower Labs · Jun 12, 2026
It is yet another day in this parallel universe of security, where the devices we bolt onto the edge of our networks to keep the bad people out are, with remarkable consistency, the exact thing that let the bad people in.While we’ve seemingly had a breather from
Rapid7 · Jun 08, 2026
OverviewOn June 8, 2026, Check Point published a security advisory for CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN, Mobile Access, and Spark Firewall products. The vulnerability affects deployments configured to use the deprecated IKEv1 key exchange protocol where gateways accept legacy Remote Access clients and do not require a machine certificate for connections.CVE-2026-50751, classified as improper authentication (CWE-287), has a CVSS score of 9.3. The vulnerability stems from a logic flow weakness in how Remote Access and Mobile Access components validate certificates during IKEv1 key exchange; successful exploitation allows an unauthenticated attacker to establish a VPN session without providing valid credentials. Per the vendor, additional post-authentication activity is required to access internal resources or escalate privileges.Check Point has indicated that CVE-2026-50751 is being actively exploited in the wild, with observed activity dating back to May 7, 2026 and an increase in early June. The vendor characterizes the campaign as limited in scope, affecting several dozen organizations. At least one incident has been linked to a Qilin ransomware affiliate, which Check Point assesses with medium confidence. Rapid7 has observed at least one case with high confidence that can be attributed to CVE-2026-50751.Separately, during its investigation Check Point identified a related vulnerability, CVE-2026-50752 (CVSS 7.4), in the same IKEv1 code path that could enable a man-in-the-middle attack against site-to-site VPN tunnels under certain configurations. No exploitation of CVE-2026-50752 has been observed.Check Point VPN products have been targeted by zero-day vulnerabilities in the past. In May 2024, CVE-2024-24919, a high-severity information disclosure vulnerability in Check Point Quantum Security Gateways, was exploited in the wild and subsequently added to the CISA Known Exploited...
TheHackerNews · Jun 08, 2026
Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protocol. The vulnerability, tracked as CVE-2026-50751 (CVSS score: 9.3), is a case of a logic flow weakness in certificate validation that allows an unauthenticated remote attacker to bypass user
All CISA Advisories · Jun 08, 2026
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42271 BerriAI LiteLLM Command Injection Vulnerability CVE-2026-50751 Check Point Security Gateway Improper Authentication Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Check Point Blog · Jun 08, 2026
Check Point Research has identified active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. By exploiting a logic flaw in certificate validation, an attacker can establish a VPN session without possession of a valid password, effectively bypassing authentication requirements. Additional post-authentication activity is required to access internal resources or escalate privileges. To date, the observed exploitation has been limited to a few dozen targeted organizations globally. One case involved confirmed post-compromise activity associated with Qilin ransomware affiliate. Customers using IKEv1 key […] The post Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) appeared first on Check Point Blog.
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-06-16 11:08:33 UTC · 0 stars
CVE-2026-50751 Mass Scanner
github · Created 2026-06-12 14:25:40 UTC · 1 stars
CVE-2026-50751 — Check Point IKEv1 Authentication Bypass
github · Created 2026-06-10 21:10:44 UTC · 0 stars
github · Created 2026-06-10 15:32:15 UTC · 0 stars
CVE-2026-50751 Check Point IKEv1 vulnerability scanner
github · Created 2026-06-10 14:16:22 UTC · 0 stars
Vulnerability: Logic flow weakness in Remote Access and Mobile Access
github · Created 2026-06-08 13:26:38 UTC · 1 stars
Mitigation scripts for CVE-2026-50751
nuclei · Created Unknown
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
04:30 UTC about 1 month ago04:30 UTC · about 1 month ago
Nuclei template available
Scanner coverage available
-
20:41 UTC about 1 month ago20:41 UTC · about 1 month ago
KEV confirmed by CVE
Exploitation attested by an external source
-
20:20 UTC about 1 month ago20:20 UTC · about 1 month ago
KEV confirmed by All CISA Advisories
Exploitation attested by an external source
-
20:00 UTC about 1 month ago20:00 UTC · about 1 month ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
19:20 UTC about 1 month ago19:20 UTC · about 1 month ago
KEV confirmed by Rapid7
Exploitation attested by an external source
-
15:20 UTC about 1 month ago15:20 UTC · about 1 month ago
KEV confirmed by TheHackerNews
Exploitation attested by an external source
-
15:14 UTC about 1 month ago15:14 UTC · about 1 month ago
Used in qilin ransomware malware
Exploit observed in malware
-
14:20 UTC about 1 month ago14:20 UTC · about 1 month ago
Added to KEVIntel KEV Feed
High-confidence, third-party attested exploitation
-
13:26 UTC about 1 month ago13:26 UTC · about 1 month ago
Public PoC available
Public proof-of-concept code published
-
11:07 UTC about 1 month ago11:07 UTC · about 1 month ago
CVE published
Vulnerability disclosed publicly
-
09:42 UTC about 1 month ago09:42 UTC · about 1 month ago
CVE ID reserved
Identifier reserved by the CNA
-
14:26 UTC 2 months ago14:26 UTC · 2 months ago
Indicators of compromise added (9)
Indicators of compromise recorded
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2026-50751
{
"cve_id": "CVE-2026-50751",
"title": "User Authentication Bypass in VPN Remote Access and Mobile Access",
"affected_vendor": "checkpoint",
"affected_product": "Quantum Security Gateway, Spark Firewalls",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 9.3,
"epss_score": 0.70099,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}