- Products
- Learn
- Local User Groups
- Partners
- More
Simplify Admin Operations with R82.20
Wed, 19 August @ 5pm CET/11am EDT
The industry's first AI Network Firewall
Securing AI traffic, everywhere
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
READY OR NOT: Securing the AI Enterprise
AI Research & Threat Landscape
CheckMates Go:
That's Serious Stuff!
By exploiting a logic flaw in certificate validation, an attacker can establish a VPN session without possession of a valid password, effectively bypassing authentication requirements.
Additional post-authentication activity is required to access internal resources or escalate privileges.
To date, the observed exploitation has been limited to a few dozen targeted organizations globally. One case involved confirmed post-compromise activity associated with Qilin ransomware affiliate.
Customers using IKEv1 key exchange protocol are strongly encouraged to apply the available security updates immediately.
CVE-2026-50751 is an authentication bypass on VPN Remote Access and Mobile Access in deprecated IKEv1 key exchange. An attacker can bypass user authentication by exploiting a logic flow weakness in the Remote Access and Mobile Access certificate validation and establish a remote access VPN connection without a valid user password. Check Point has observed active exploitation of this vulnerability in the wild.
As part of the CVE-2026-50751 investigation, Check Point Research conducted an extended review of the affected VPN components using BLAST, our agentic application security platform. This process identified and enabled the remediation of an additional vulnerability, CVE-2026-50752.
CVE-2026-50752 impacts certificate validation in deprecated IKEv1 key exchange and may allow man-in-the-middle interference with site-to-site VPN communications under specific conditions.
Check Point has not observed exploitation of this vulnerability in the wild; customers are advised to apply updates to mitigate potential exposure.
The identification of CVE-2026-50752 underscores the importance of combining threat intelligence, security research, and AI-assisted code analysis to proactively detect and remediate vulnerabilities before they can be weaponized.
For more details, please read the relevant blog entry.
Additional technical information, suspicious IPs, and indicators can also be found on the security knowledge base articles here:
Can you paste the SKs here please? The Support Portal is having issues for our team.
Same, unable to open the SK pages. Blog is working, also got news letter.
Should work now for everyone
Did not get this newsletter, where do i sign up ?
SK's are unreachable
Results 1-10 of 57 for sk1803
We couldn't find anything for sk185033
Query was automatically corrected to sk1803
Hi Val,
I suspect the Checkpoint site is overwhelmed with people checking, can you confirm if Jumbo's are updated for Gaia, and if Spark Builds are also updated?
I don't think so, this is a new CVE, which requires a specific hotfix.
Guess you saw already, that bunch of SPARKs got new firmwares...
Apparently CheckPoint is another victim of the good old SlashDot Effect. It would have been wise to inform the partners a bit BEFORE the customers to give us a head start. Now, we as a partner are in the blind.
Customer or partner, should not matter who goes first, does not work like that.
Here we can track the status of the outage:
https://status.checkpoint.com/incidents/v1nqhm198k42
Thanks for your feedback. Both customers and partners were informed about this before this post was published.
I understand the sentiment, but those are customers who are affected, and there is sense of urgency.
I got the email today at 13:31 after my security consultant got it yesterday @ 13:27 and forwarded it on - 24 hours later does not feel like a sense of urgency to me! The subject date changed but the content was otherwise the same.
Links should work now, we experienced a brief ddos situation
These links are not working:
These links are working:
https://support.checkpoint.com/results/sk/sk185033
https://support.checkpoint.com/results/sk/sk185035
Just triple-checked. Please try them.
They are working now! Thank you!
Great to hear, and sorry for the issues before.
Link to the hotfix seems down still?
Also would I be correct in saying the specific Hotfix is only required on the GW appliance?
Both are not working right now.
FWIW - both links still showing as under maintenance from Southern Africa. Perhaps someone can repost the SK content here?
Links are still down it looks like. Under Maintenance.
So, does clearing "Allow older clients to connect to this gateway" is sufficient to not be vulnerable, even in IKEv1?
Is the hotfix on top of this still necessary or only for those who can't apply one of the other options?
I know it's best to patch on top of mitigations, just checking if we need to start to tour the country for updates like right now.
Which clients are disallowed when I deselect this option?
"Allow older clients to connect to this gateway" <- should mainly affect clients which are not from checkpoint... i have disabled this option long ago, and still have securemote clients back to version E80.90 which still work...
I have a customer still using SecureRemote E80.62 986000452. Do you think it might affect?
the oldest one i have is SecureRemote E80.72, which is still working with "Allow older clients to connect to this gateway" disabled
Seems like both links are not working .
Maintenance Window appears, looks like overloaded.
that's wha I think, so it will be just a case of waiting.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 34 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 18 Aug 2026 @ 01:00 PM (BRT)
IA: a nova linha de frente do endpoint - Todo ataque tem um antes, um durante e depois.Thu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 20 Aug 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #11: SD-WAN Simplicity and Scalability in 2026Thu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 18 Aug 2026 @ 01:00 PM (BRT)
IA: a nova linha de frente do endpoint - Todo ataque tem um antes, um durante e depois.Thu 20 Aug 2026 @ 11:00 AM (EDT)
Tips and Tricks 2026 #11: SD-WAN Simplicity and Scalability in 2026Thu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 25 Aug 2026 @ 05:00 PM (CEST)
The State of Ransomware Q2 2026: This Quarter's Trends, and Their Impact on Your DefensesThu 20 Aug 2026 @ 08:30 AM (COT)
Medellin: Workspace Evolution: Hybrid Mesh Management - Visibilidad, Automatización e IAThu 20 Aug 2026 @ 06:00 PM (COT)
Medellin: Workspace Intelligence: IA Generativa en Acción para Equipos de SeguridadAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY