
CVE-2026-50751
CVE-2026-50751 is a critical authentication bypass vulnerability affecting Check Point Quantum Security Gateway deployments configured with the legacy IKEv1 Remote Access VPN protocol.
The flaw allows an unauthenticated attacker to establish a VPN session without possessing a valid user password, potentially granting unauthorized access to internal network resources.
An attacker can:
┌─────────────────────┐
│ External Attacker │
└──────────┬──────────┘
│
▼
┌─────────────────────┐
│ Check Point Gateway │
│ VPN (IKEv1) │
└──────────┬──────────┘
│
▼
┌─────────────────────┐
│ Authentication │
│ Validation Flaw │
└──────────┬──────────┘
│
▼
┌─────────────────────┐
│ Authentication │
│ Successfully Bypassed│
└──────────┬──────────┘
│
▼
┌─────────────────────┐
│ VPN Session Created │
└──────────┬──────────┘
│
▼
┌─────────────────────┐
│ Internal Network │
│ Access Achieved │
└─────────────────────┘
Reports indicate that the vulnerability has been actively exploited against targeted organizations.
Potential attacker objectives include:
✓ Disable IKEv1
✓ Migrate to IKEv2
✓ Apply Check Point hotfixes
✓ Audit VPN logs
✓ Rotate exposed credentials
✓ Monitor suspicious VPN activity
Remote Access VPN
│
▼
Disable IKEv1
│
▼
Enable IKEv2
│
▼
Certificate Validation
│
▼
Continuous Monitoring
Security teams should monitor for:
| Category | Rating |
|---|---|
| Confidentiality | 🔴 High |
| Integrity | 🔴 High |
| Availability | 🟠 Medium |
| Exploit Complexity |
| Date | Event |
|---|---|
| May 2026 | Active exploitation observed |
| 2026 | CVE assigned |
| 2026 | Vendor hotfix released |
Check Point Quantum Security Gateway
│
├── Remote Access VPN
│
└── Mobile Access VPN
│
└── IKEv1 Enabled
Organizations still relying on legacy IKEv1 VPN configurations should prioritize migration to IKEv2 and apply available vendor patches immediately.
Disable IKEv1 • Patch Systems • Monitor VPN Access
⭐ If this repository helped you, consider giving it a star.
| Field | Value |
|---|
| CVE | CVE-2026-50751 |
| Type | Authentication Bypass |
| CWE | CWE-287 |
| Attack Vector | Remote |
| Authentication Required | No |
| User Interaction | None |
| Affected Component | IKEv1 Remote Access VPN |
| Product | Check Point Quantum Security Gateway |
| 🟢 Low |
| Attack Surface | 🔴 Internet Facing |