CVE-2026-50751
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Jun 8, 2026
- US federal agencies must remediate it by Jun 11, 2026 (BOD 22-01)
- Attacked on the day of disclosure
- Confirmed by sensors, not only by reports
- Used in ransomware campaigns
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Sep 4, 2026 Aug 10, 2026 Jul 30, 2026 Jul 22, 2026 Jul 20, 2026 Jul 18, 2026
CVSS score9.3 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NWeakness type (CWE)CWE-287
Vendorscheckpoint
Affected products
| Vendors | Product | Versions |
|---|---|---|
| checkpoint | gaia os | < r81.20 |
| checkpoint | gaia embedded | < r81.10.17 |
| checkpoint | quantum spark 1530 | - |
| checkpoint | quantum spark 1550 | - |
| checkpoint | quantum spark 1570 | - |
| checkpoint | quantum spark 1570r | - |
| checkpoint | quantum spark 1590 | - |
| checkpoint | quantum spark 1595r | - |
| checkpoint | quantum spark 1600 | - |
| checkpoint | quantum spark 1800 | - |
| checkpoint | quantum spark 1900 | - |
| checkpoint | quantum spark 2000 | - |
| checkpoint | quantum spark 1535 | - |
| checkpoint | quantum spark 1555 | - |
| checkpoint | quantum spark 1575 | - |
| checkpoint | quantum spark 1575r | - |
| checkpoint | quantum spark 2530 | - |
| checkpoint | quantum spark 2550 | - |
| checkpoint | quantum spark 2560 | - |
| checkpoint | quantum spark 2570 | - |
| checkpoint | quantum spark 2580 | - |
| checkpoint | quantum spark 2590 | - |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
