CVE-2026-50751: Check Point Security Gateway Improper Authentication Vulnerability
Critical severity, CVSS 9.3. Actively exploited: in CISA KEV since 2026-06-08. EPSS: 85.3% chance of exploitation in the next 30 days.
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Affected products
- Check Point Gaia Embedded: from r80.20.00, before r81.10.17 (fixed in r81.10.17); version r81.10.17 only; from r80.20.00, before r82.00.10 (fixed in r82.00.10); version r82.00.10 only
- Check Point Gaia OS: from r80.40, before r81.20 (fixed in r81.20); version r81.20 only; version r82 only; version r82.10 only
Published 2026-06-08. Last modified 2026-08-04.