CVE-2026-50751

Analyzed
Published: 08 Jun 2026, 11:07
Last modified:10 Jun 2026, 13:37

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.3 CRITICAL
v3.1 (cve.org)
EPSS Score
70.1% CRITICAL
70% probability 0.00%
KEV
Listed
CIRCL • CISA
2 listings
Ransomware
Known Use
Public exploits
None found
Dark Web
Not detected

Timeline

08 Jun 2026, 11:07
Published
Vulnerability first disclosed
08 Jun 2026, 00:00
Added to CIRCL KEV
Added to Known Exploited Vulnerabilities catalog
08 Jun 2026, 00:00
Added to CISA KEV
Check Point Security Gateway Improper Authentication Vulnerability
10 Jun 2026, 13:37
Last Modified
Vulnerability information updated
11 Jun 2026, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CVSS Metrics

  • v3.1CRITICALScore: 9.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

EPSS Trends

Current EPSS score: 70.10% Percentile: 99%

Techniques & Countermeasures

  • CWE-287Improper Authentication

    When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Systems

  • checkpointgaia_embedded

    ≥ r80.20.00, < r81.10.17 | r81.10.17 | r81.10.17:build_996004508 | r81.10.17:build_996004620 | r81.10.17:build_996004653 | r81.10.17:build_996004721 | r81.10.17:build_996004892 | ≥ r80.20.00, < r82.00.10 | r82.00.10 | r82.00.10:build_998001559 | r82.00.10:build_998001562 | r82.00.10:build_998002110 | r82.00.10:build_998002112 | r82.00.10:build_998002133 | r82.00.10:build_998002203

  • checkpointgaia_os

    ≥ r80.40, < r81.20 | r81.20 | r81.20:take_10 | r81.20:take_101 | r81.20:take_103 | r81.20:take_105 | r81.20:take_111 | r81.20:take_113 | r81.20:take_115 | r81.20:take_118 | r81.20:take_119 | r81.20:take_120 | r81.20:take_122 | r81.20:take_126 | r81.20:take_127 | r81.20:take_14 | r81.20:take_141 | r81.20:take_24 | r81.20:take_26 | r81.20:take_38 | r81.20:take_41 | r81.20:take_43 | r81.20:take_45 | r81.20:take_53 | r81.20:take_54 | r81.20:take_65 | r81.20:take_70 | r81.20:take_76 | r81.20:take_79 | r81.20:take_8 | r81.20:take_84 | r81.20:take_89 | r81.20:take_90 | r81.20:take_92 | r81.20:take_96 | r81.20:take_98 | r81.20:take_99 | r82 | r82:take_10 | r82:take_103 | r82:take_12 | r82:take_14 | r82:take_18 | r82:take_19 | r82:take_25 | r82:take_33 | r82:take_34 | r82:take_36 | r82:take_39 | r82:take_41 | r82:take_43 | r82:take_44 | r82:take_60 | r82:take_73 | r82:take_91 | r82.10 | r82.10:take_19 | r82.10:take_6

  • checkpointquantum security gateway

    R82.10 with Jumbo Hotfix Take 19 or below | R82 with Jumbo Hotfix Take 103 or below | R81.20 with Jumbo Hotfix Take 141 or below | R81.10, R81, and R80.40

  • checkpointspark firewalls

    R80.20.X, R81.10.X, and R82.00.X

References (3)