Junglewise Threat Intelligence

CVE-2026-50751: Check Point VPN authentication bypass in IKEv1 key exchange

CVE-2026-50751 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-06-08

Executive brief

Check Point Security Gateways are used to provide secure remote access to corporate networks. A flaw in how these gateways verify identities during the login process allows an unauthorized person to connect to the corporate VPN without needing a valid password. This could allow an attacker to gain full access to internal company resources and sensitive data.

Technical details

An improper authentication vulnerability (CWE-287) exists in Check Point Security Gateway's Remote Access and Mobile Access components. The flaw is rooted in a logic flow weakness during certificate validation within the deprecated IKEv1 key exchange protocol. An unauthenticated remote attacker can exploit this by initiating an IKEv1 session, allowing them to bypass standard user authentication requirements. Successful exploitation enables the attacker to establish a fully functional remote access VPN connection without providing a valid password. This vulnerability has been reported as exploited in the wild.

Affected products

  • Check Point Security Gateway

Timeline

  • 2026-06-08: disclosed
  • 2026-06-08: advisory
  • 2026-06-08: exploited: Reported as exploited in the wild at the time of publication.

Related threats