CVE-2026-50752: Check Point Quantum Security Gateway
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.
Affected products
- Check Point Quantum Security Gateway: up to and including R82.10; up to and including R81.20
- Check Point Spark Firewalls
Published 2026-06-08. Last modified 2026-07-23.