CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2026-50751

CVSS 9.3v3.1pub. 2026-06-08upd. 2026-08-04

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

🤖 AI Analysis
How it works

A logic error (CWE-287) in the certificate validation process during IKEv1 negotiation causes the user identity verification mechanism to be bypassed. An attacker, without possessing the correct password, is able to conduct an IKEv1 session in such a way that the system incorrectly recognizes authentication as successfully completed. As a result, a remote attacker can establish a full-fledged VPN connection within the Remote Access or Mobile Access functions.

Impact

An attacker can gain unauthorized access to an organization's internal network through a VPN tunnel, creating a risk of confidential data disclosure (High Confidentiality) and limited modifications to protected resources (Low Integrity). The vulnerability enables lateral movement within the network.

Mitigation & patch

The hotfix provided by Check Point should be applied immediately in accordance with the recommendations in article sk185033 (https://support.checkpoint.com/results/sk/sk185033). Additionally, it is recommended to disable support for the deprecated IKEv1 protocol wherever it is not absolutely required, and to migrate to IKEv2.

Who is affected

Check Point products supporting Remote Access VPN and Mobile Access functions with deprecated IKEv1 protocol support enabled — specific versions indicated in vendor references (sk185033).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
  • Checkpoint Gaia Embedded

    OS
    Checkpoint
    r81.10.17r82.00.10r80.20.00 – r82.00.10 (excl.)r80.20.00 – r81.10.17 (excl.)
  • Checkpoint Gaia Os

    OS
    Checkpoint
    r81.20r82r82.10r80.40 – r81.20 (excl.)
  • Checkpoint Quantum Spark 1530

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1535

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1550

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1555

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1570

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1570r

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1575

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1575r

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1590

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1595r

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1600

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1800

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 1900

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 2000

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 2530

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 2550

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 2560

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 2570

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 2580

    HW
    Checkpoint
    all versions
  • Checkpoint Quantum Spark 2590

    HW
    Checkpoint
    all versions

CISA KEV — detailsi

Vendori
Check Point
Producti
Security Gateway
Added to KEVi
June 8, 2026
Remediation deadline (US Federal)i
June 11, 2026(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 11 czerwca 2026
Tags
VPNAuth Bypass
CWE
References

Related vulnerabilities

CVE-2024-24914HIGH8.0same product

Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Secu...

CVE-2024-52885MEDIUM5.0same product

The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an a...

CVE-2024-52888MEDIUM5.4same product

For an authenticated end-user the portal may run a script while attempting to display a directory or some file...

CVE-2024-24911MEDIUM5.3same product

In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unex...

CVE-2021-30361MEDIUM6.7same product

The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Cli...