Umbra Wiki cve cve/CVE-2026-50751
Back to wiki

CVE-2026-50751 — Check Point Security Gateway Improper Authentication Vulnerability

provenance: imported · CVE: CVE-2026-50751

CVE-2026-50751: Check Point Security Gateway Improper Authentication Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Check Point
Product Security Gateway
Date added 2026-06-08
Due date 2026-06-11
Ransomware campaign use Known

Description

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Required action (CISA)

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Notes

https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ ; https://support.checkpoint.com/results/sk/sk185033?_gl=11wqeqhc_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM. ; https://nvd.nist.gov/vuln/detail/CVE-2026-50751

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-50751
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog