Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-50751 |
| Alert Source | Check Point Security Advisory (sk185033) |
| CVE Publication Year | 2026 |
| Date Published | 2026-06-08 |
| Vendor | Check Point |
| Product | Quantum Security Gateway |
| CVSS Score | 9.3 (critical) |
| CISA KEV | No |
| Active exploitation | Yes — confirmed by Check Point |
| Ransomware | Not confirmed |
Vulnerability Description
Check Point has confirmed active exploitation of a user authentication bypass vulnerability affecting VPN Remote Access and Mobile Access on certain gateway configurations, through the deprecated IKEv1 key exchange. An unauthenticated remote attacker can bypass authentication controls to gain unauthorized access to the protected environment.
A hotfix has been released and Check Point urges all VPN customers to install it as soon as possible. The same hotfix also addresses CVE-2026-50752 (Site-to-Site VPN certificate bypass).
Affected configurations — gateways are suspected vulnerable if all conditions are met:
- Products: Check Point Firewalls, Spark Firewalls
- Firewall versions: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
- Spark Firewall versions: R80.20.XX (EOS), R81.10.X, R82.00.X
- VPN Remote-Access or Mobile-Access enabled, and deprecated IKEv1 key exchange enabled
Required Actions
Immediately install the Check Point hotfix on all affected Security Gateways (it addresses both CVE-2026-50751 and CVE-2026-50752). Where immediate patching is not possible, follow Check Point’s alternative mitigations (e.g. disabling the deprecated IKEv1 key exchange) and review indicators of compromise in the advisory. Given confirmed active exploitation, treat this as an emergency change.
Who Is Affected?
This vulnerability affects Quantum Security Gateway by Check Point. Check if your Check Point or Spark Firewall runs an affected version with VPN Remote-Access / Mobile-Access and IKEv1 enabled, and apply the hotfix immediately.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
