CVE-2026-50751

Confirmed PUBLISHED

User Authentication Bypass in VPN Remote Access and Mobile Access

checkpoint · Quantum Security Gateway, Spark Firewalls

6 hours faster than CISA KEV

Exploited in the wild Used in malware PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.3 Critical EPSS 70.1%

At a Glance

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

qilin ransomware malware cisa nuclei_scanner
CVE Published
Jun 08, 2026
Exploitation Reported
Jun 08, 2026
CVSS
9.3 Critical
EPSS
70.1%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
checkpoint
Quantum Security Gateway

R82.10 with Jumbo Hotfix Take 19 or below

Affected
checkpoint
Quantum Security Gateway

R82 with Jumbo Hotfix Take 103 or below

Affected
checkpoint
Quantum Security Gateway

R81.20 with Jumbo Hotfix Take 141 or below

Affected
checkpoint
Quantum Security Gateway

R81.10, R81, and R80.40

Affected
checkpoint
Spark Firewalls

R80.20.X, R81.10.X, and R82.00.X

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.