Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
_Val_
Admin
Admin

ACTION REQUIRED – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)

Check Point Research has identified active exploitation of CVE-2026-50751, a critical authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access deployments configured to use the deprecated IKEv1 key exchange protocol.

 

By exploiting a logic flaw in certificate validation, an attacker can establish a VPN session without possession of a valid password, effectively bypassing authentication requirements.

Additional post-authentication activity is required to access internal resources or escalate privileges.

To date, the observed exploitation has been limited to a few dozen targeted organizations globally. One case involved confirmed post-compromise activity associated with Qilin ransomware affiliate.

Customers using IKEv1 key exchange protocol are strongly encouraged to apply the available security updates immediately.

 

CVE Details

 

CVE-2026-50751 is an authentication bypass on VPN Remote Access and Mobile Access in deprecated IKEv1 key exchange. An attacker can bypass user authentication by exploiting a logic flow weakness in the Remote Access and Mobile Access certificate validation and establish a remote access VPN connection without a valid user password. Check Point has observed active exploitation of this vulnerability in the wild.

Enhancing Security with BLAST (Check Point’s Agentic AI Code Security Platform)

 

As part of the CVE-2026-50751 investigation, Check Point Research conducted an extended review of the affected VPN components using BLAST, our agentic application security platform. This process identified and enabled the remediation of an additional vulnerability, CVE-2026-50752.

CVE-2026-50752 impacts certificate validation in deprecated IKEv1 key exchange and may allow man-in-the-middle interference with site-to-site VPN communications under specific conditions.

Check Point has not observed exploitation of this vulnerability in the wild; customers are advised to apply updates to mitigate potential exposure.

The identification of CVE-2026-50752 underscores the importance of combining threat intelligence, security research, and AI-assisted code analysis to proactively detect and remediate vulnerabilities before they can be weaponized.

For more details, please read the relevant blog entry.
 
Additional technical information, suspicious IPs, and indicators can also be found on the security knowledge base articles here: 

https://support.checkpoint.com/results/sk/sk185033 

https://support.checkpoint.com/results/sk/sk185035 

(1)
120 Replies
StackCap43382
Collaborator
Collaborator

Can you paste the SKs here please? The Support Portal is having issues for our team.

CCSME, CCTE, CCME, CCVS
Lesley
MVP Platinum
MVP Platinum

Same, unable to open the SK pages. Blog is working, also got news letter. 

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
_Val_
Admin
Admin

Should work now for everyone

 

0 Kudos
nooni
Collaborator
Collaborator

Did not get this newsletter, where do i sign up ?

0 Kudos
Alex-
MVP Silver
MVP Silver

SK's are unreachable

Results 1-10 of 57 for sk1803
We couldn't find anything for sk185033

Query was automatically corrected to sk1803
0 Kudos
genisis__
MVP Silver
MVP Silver

Hi Val,


I suspect the Checkpoint site is overwhelmed with people checking, can you confirm if Jumbo's are updated for Gaia, and if Spark Builds are also updated?

0 Kudos
nmelay2
Collaborator

I don't think so, this is a new CVE, which requires a specific hotfix.

0 Kudos
freshwater84
Contributor

Guess you saw already, that bunch of SPARKs got new firmwares...

0 Kudos
Arne_Boettger
Collaborator
Collaborator

Apparently CheckPoint is another victim of the good old SlashDot Effect. It would have been wise to inform the partners a bit BEFORE the customers to give us a head start. Now, we as a partner are in the blind.

(2)
Lesley
MVP Platinum
MVP Platinum

Customer or partner, should not matter who goes first, does not work like that.

Here we can track the status of the outage:

https://status.checkpoint.com/incidents/v1nqhm198k42

-------
Please press "Accept as Solution" if my post solved it 🙂
(2)
_Val_
Admin
Admin

Thanks for your feedback. Both customers and partners were informed about this before this post was published. 

 

I understand the sentiment, but those are customers who are affected, and there is sense of urgency. 

(1)
Paul_Stephenson
Contributor

I got the email today at 13:31 after my security consultant got it yesterday @ 13:27 and forwarded it on - 24 hours later does not feel like a sense of urgency to me! The subject date changed but the content was otherwise the same.

0 Kudos
(1)
_Val_
Admin
Admin

Links should work now, we experienced a brief ddos situation 

Dan_Moesch
Contributor

0 Kudos
_Val_
Admin
Admin

These links are working:

https://support.checkpoint.com/results/sk/sk185033 

https://support.checkpoint.com/results/sk/sk185035 

 

Just triple-checked. Please try them.

0 Kudos
Dan_Moesch
Contributor

They are working now!  Thank you!   

_Val_
Admin
Admin

Great to hear, and sorry for the issues before.

0 Kudos
genisis__
MVP Silver
MVP Silver

Link to the hotfix seems down still?
Also would I be correct in saying the specific Hotfix is only required on the GW appliance?

0 Kudos
SR141287
Explorer

Both are not working right now.

0 Kudos
Ruan_Kotze
MVP Gold
MVP Gold

FWIW - both links still showing as under maintenance from Southern Africa.  Perhaps someone can repost the SK content here?

0 Kudos
Sbolton
Contributor

Links are still down it looks like. Under Maintenance.

0 Kudos
Alex-
MVP Silver
MVP Silver

So, does clearing "Allow older clients to connect to this gateway" is sufficient to not be vulnerable, even in IKEv1?

Is the hotfix on top of this still necessary or only for those who can't apply one of the other options?

I know it's best to patch on top of mitigations, just checking if we need to start to tour the country for updates like right now.

Steffen_Appel
Advisor

Which clients are disallowed when I deselect this option? 

0 Kudos
GHaider
Contributor

"Allow older clients to connect to this gateway" <- should mainly affect clients which are not from checkpoint... i have disabled this option long ago, and still have securemote clients back to version E80.90 which still work...

(1)
Teddy_Brewski
Advisor

I have a customer still using SecureRemote E80.62 986000452. Do you think it might affect?

0 Kudos
GHaider
Contributor

the oldest one i have is SecureRemote E80.72, which is still working with "Allow older clients to connect to this gateway" disabled

0 Kudos
Kervans110480
Explorer

0 Kudos
PeterH
Contributor

Maintenance Window appears, looks like overloaded.

0 Kudos
genisis__
MVP Silver
MVP Silver

that's wha I think, so it will be just a case of waiting.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events