What it is
CVE-2026-50751 is an unauthenticated User Authentication Bypass in VPN Remote Access and Mobile Access affecting checkpoint Quantum Security Gateway, Spark Firewalls. A logic flow weakness in Remote Access and Mobile...
Vulnerability report
User Authentication Bypass in VPN Remote Access and Mobile Access
checkpoint / Quantum Security Gateway · R82.10 with Jumbo Hotfix Take 19 or below
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-50751 is an unauthenticated User Authentication Bypass in VPN Remote Access and Mobile Access affecting checkpoint Quantum Security Gateway, Spark Firewalls. A logic flow weakness in Remote Access and Mobile...
Is it exploited?
Yes. KEV Intelligence tracks this CVE as a known exploited vulnerability. Confidence is confirmed.
Who is affected?
checkpoint / Quantum Security Gateway r82.10 with jumbo hotfix take 19 or below.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
Check Point Blog
Independent exploitation attestation added to the KEV Intelligence record.
Check Point Blog
Malware families have been linked to exploitation of this CVE.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the KEV Intelligence Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| Check Point Blog First | 2026-06-08 14:20 UTC |
| TheHackerNews | 2026-06-08 15:20 UTC |
| Rapid7 | 2026-06-08 19:20 UTC |
| CISA | 2026-06-08 20:00 UTC |
| All CISA Advisories | 2026-06-08 20:20 UTC |
| CVE | 2026-06-08 20:41 UTC |
Operational indicators for this CVE are listed under Detection.
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Raw values available in Pro and Enterprise.
Nuclei template detected 17 Jun 2026.
View Nuclei template (opens in new tab)No KEV Intelligence virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →Operational indicators linked to exploitation of this CVE. IoCs age over time — especially IP addresses.
| Type | Indicator | First Seen | Last Seen | Age | Source |
|---|---|---|---|---|---|
| IP Stale |
45.77.149.152
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 3 months ago | Source |
| IP Stale |
209.182.225.136
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 3 months ago | Source |
| IP Stale |
38.60.157.139
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 3 months ago | Source |
| IP Stale |
162.33.177.101
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 3 months ago | Source |
| IP Stale |
45.76.26.42
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 3 months ago | Source |
| IP Stale |
144.208.127.155
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 3 months ago | Source |
| IP Stale |
38.54.88.201
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 3 months ago | Source |
| IP Stale |
38.54.107.167
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 3 months ago | Source |
| IP Stale |
66.42.99.200
|
2026-05-07 14:26 UTC | 2026-05-07 14:26 UTC | 3 months ago | Source |
Scanner and exploit-framework references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-50751.yaml | 17 Jun 2026 |
Risk and context
CVSS v4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
EPSS
82.6%
Recent mention · Rapid7
OverviewOn July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232, an authentication bypass in the SmartConsole login...
Read full advisoryCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Recent mention · Rapid7
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the WildRapid7 · 23 Jul 2026
OverviewOn July 22, 2026, Check Point published a security advisory for multiple vulnerabilities affecting Security Management, Multi-Domain Management, and firewall products. The most urgent of these is CVE-2026-16232, an authentication bypass in the SmartConsole login process classified as improper authentication (CWE-287). CVE-2026-16232 has been assigned a critical CVSS score of 9.1. The vulnerability allows an unauthenticated remote attacker to obtain an application login token and authenticate to the management server with full administrative privileges, enabling modification of...
Recent mention · Watchtower Labs
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)Watchtower Labs · 12 Jun 2026
It is yet another day in this parallel universe of security, where the devices we bolt onto the edge of our networks to keep the bad people out are, with remarkable consistency, the exact thing that let the bad people in.While we’ve seemingly had a breather from
Recent mention · Rapid7
Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)Rapid7 · 08 Jun 2026
OverviewOn June 8, 2026, Check Point published a security advisory for CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN, Mobile Access, and Spark Firewall products. The vulnerability affects deployments configured to use the deprecated IKEv1 key exchange protocol where gateways accept legacy Remote Access clients and do not require a machine certificate for connections.CVE-2026-50751, classified as improper authentication (CWE-287), has a CVSS score of 9.3. The vulnerability stems from a logic flow weakness in how Remote Access and...
Recent mention · TheHackerNews
Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 SetupsTheHackerNews · 08 Jun 2026
Check Point has warned of active exploitation of a critical vulnerability impacting Remote Access VPN and Mobile Access deployments that are configured to use the deprecated IKEv1 key exchange protocol. The vulnerability, tracked as CVE-2026-50751 (CVSS score: 9.3), is a case of a logic flow weakness in certificate validation that allows an unauthenticated remote attacker to bypass user
Recent mention · All CISA Advisories
CISA Adds Two Known Exploited Vulnerabilities to CatalogAll CISA Advisories · 08 Jun 2026
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42271 BerriAI LiteLLM Command Injection Vulnerability CVE-2026-50751 Check Point Security Gateway Improper Authentication Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common...
Recent mention · Check Point Blog
Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)Check Point Blog · 08 Jun 2026
Check Point Research has identified active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol. By exploiting a logic flaw in certificate validation, an attacker can establish a VPN session without possession of a valid password, effectively bypassing authentication requirements. Additional post-authentication activity is required to access internal resources or escalate privileges. To date, the observed exploitation has been limited...
These PoCs are unverified and could contain malware. Use at your own risk.
nuclei · Created Unknown
Timeline
Public proof-of-concept code published
Scanner coverage available
Exploitation attested by an external source
Exploitation attested by an external source
Listed in the CISA Known Exploited Vulnerabilities catalog
Exploitation attested by an external source
Exploitation attested by an external source
Exploit observed in malware
High-confidence, third-party attested exploitation
Vulnerability disclosed publicly
Identifier reserved by the CNA
Indicators of compromise recorded
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-50751
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-50751",
"confidence": "Confirmed",
"cvss_score": 9.3,
"cvss_estimated": false,
"epss_score": 0.82554,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}
Early warning alerts
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.