CVE-2026-50751

CRITICAL(9.3)KEVRansomwareLikely Exploited

Check Point Security Gateway Improper Authentication Vulnerability

Description

CVE-2026-50751 is a critical authentication bypass vulnerability in Check Point Security Gateway. A logic-flow weakness in Remote Access and Mobile Access certificate validation within the deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. Because the attacker can gain VPN access into the protected network without credentials, CVE-2026-50751 undermines the core security boundary the gateway is meant to enforce. It is rated CVSS 9.3 (Critical) with a changed scope, is listed in the CISA KEV catalog, and has a known association with ransomware campaigns. Organizations running Check Point Security Gateway with the deprecated IKEv1 VPN protocol should apply the vendor hotfix urgently.

KEV Information

Vendor
Check Point
Product
Security Gateway
Date Added
June 8, 2026
Due Date
June 11, 2026
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
4.7

CWEs

Affected Products

VendorProductVersion
checkpointgaia os>= r80.40, < r81.20; r81.20; r82; r82.10
checkpointgaia embedded>= r80.20.00, < r81.10.17; r81.10.17; >= r80.20.00, < r82.00.10; r82.00.10

References

Weakness Type

CWE-287: Improper Authentication

CVE-2026-50751 is classified under CWE-287 — Improper Authentication. The gateway's certificate validation logic for Remote Access and Mobile Access over deprecated IKEv1 does not correctly prove the client's claimed identity, so the authentication step can be bypassed. As a result, an attacker establishes a VPN connection without presenting a valid user password.

Learn more: CWE-287 — Improper Authentication

Impact Analysis

CVE-2026-50751 carries a CVSS 3.1 base score of 9.3 (Critical). Attack Vector (Network): the VPN endpoint is reachable and attackable remotely. Attack Complexity (Low): no special conditions are required. Privileges Required (None) and User Interaction (None): the attacker needs no credentials and no victim action. Scope (Changed): by bypassing authentication, the attacker gains access that affects resources beyond the gateway itself — namely the internal network reachable through the VPN. Confidentiality (High) with Integrity (Low) and Availability (None): the primary impact is unauthorized access to the protected network and the data reachable through the established VPN session, rather than direct destruction or outage. With an EPSS score of about 41% (98th percentile), confirmed inclusion in the KEV catalog, and a known ransomware association, the realistic risk is unauthenticated network intrusion that can serve as an initial-access foothold for ransomware operators.

Exploit Maturity

CISA has added CVE-2026-50751 to the Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, and the KEV entry flags a known ransomware association, indicating use in ransomware campaigns. The references list the Check Point hotfix article and the vendor's blog post, with no public exploit code linked, and the EPSS score is about 41% (98th percentile), indicating a high probability of exploitation. The combination of confirmed exploitation, ransomware usage, and unauthenticated VPN access makes urgent remediation essential.

Remediation

  1. Follow Check Point's and CISA's required action and apply the hotfix documented in Check Point support article sk185033 for the affected Gaia OS and Gaia Embedded versions.
  2. Where feasible, disable the deprecated IKEv1 key exchange for Remote Access and Mobile Access, since the flaw is specific to IKEv1 certificate validation.
  3. As an interim mitigation, restrict which networks can reach the VPN endpoint and increase monitoring of remote access connections until the hotfix is applied.
  4. Given the ransomware association, review VPN and authentication logs for connections established without valid credentials and hunt for signs of unauthorized internal access; rotate exposed credentials and verify offline backups.
  5. As long-term hardening, retire deprecated VPN protocols, enforce strong multi-factor authentication for remote access, and validate certificates completely (per the CWE-287 guidance).

Technical Details

The vulnerability is an instance of CWE-287 (Improper Authentication): the certificate validation logic in the deprecated IKEv1 key exchange for Remote Access and Mobile Access fails to fully prove the connecting client's identity, leaving a logic-flow gap that bypasses the password check. As reflected in the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N, an unauthenticated remote attacker negotiates an IKEv1 session that the gateway accepts despite the absence of a valid user password, establishing a remote access VPN connection into the protected environment. The changed scope reflects that the bypass grants access to the internal network behind the gateway, extending the impact beyond the gateway component itself.

Frequently Asked Questions

Is CVE-2026-50751 being actively exploited?

Yes. CVE-2026-50751 is listed in CISA's Known Exploited Vulnerabilities catalog, and the KEV entry indicates a known ransomware association. Its EPSS score of about 41% (98th percentile) further supports a high likelihood of exploitation.

What products are affected by CVE-2026-50751?

Check Point Security Gateway is affected, specifically Gaia OS and Gaia Embedded versions running the deprecated IKEv1 Remote Access and Mobile Access VPN, as detailed in Check Point article sk185033.

How do I fix CVE-2026-50751?

Apply the Check Point hotfix documented in support article sk185033 for your Gaia OS or Gaia Embedded version, and disable the deprecated IKEv1 key exchange where possible. Review remote access logs for unauthorized VPN connections.

How severe is CVE-2026-50751?

It is rated Critical with a CVSS 3.1 base score of 9.3 and a changed scope. It allows unauthenticated attackers to bypass authentication and gain VPN access to the internal network, and it is confirmed as actively exploited and associated with ransomware, so it should be remediated urgently.

CVSS Score

9.3
CRITICAL(9.3)

EPSS Score

EPSS Score82.55%
EPSS Percentile99.6%

Dates

PublishedJune 8, 2026
Last ModifiedAugust 4, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.