CVE-2026-50751

Critical9.3Published on June 8, 2026

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Jun 8, 2026
  • US federal agencies must remediate it by Jun 11, 2026 (BOD 22-01)
  • Attacked on the day of disclosure
  • Confirmed by sensors, not only by reports
  • Used in ransomware campaigns

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Source: CISA KEV · Sep 4, 2026 Aug 10, 2026 Jul 30, 2026 Jul 22, 2026 Jul 20, 2026 Jul 18, 2026

CVSS score9.3 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Weakness type (CWE)CWE-287
Vendorscheckpoint

Affected products

VendorsProductVersions
checkpointgaia os< r81.20
checkpointgaia embedded< r81.10.17
checkpointquantum spark 1530-
checkpointquantum spark 1550-
checkpointquantum spark 1570-
checkpointquantum spark 1570r-
checkpointquantum spark 1590-
checkpointquantum spark 1595r-
checkpointquantum spark 1600-
checkpointquantum spark 1800-
checkpointquantum spark 1900-
checkpointquantum spark 2000-
checkpointquantum spark 1535-
checkpointquantum spark 1555-
checkpointquantum spark 1575-
checkpointquantum spark 1575r-
checkpointquantum spark 2530-
checkpointquantum spark 2550-
checkpointquantum spark 2560-
checkpointquantum spark 2570-
checkpointquantum spark 2580-
checkpointquantum spark 2590-

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database