Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4622 articles · 179959 vulns · 37/41 feeds (7d)
← Back to list
9.3
CVE-2026-50751KEVEXPLOITEDPATCHED
checkpoint · gaia_os

User Authentication Bypass in VPN Remote Access and Mobile Access

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Affected Products

VendorProductVersions
checkpointgaia_osR82.10 with Jumbo Hotfix Take 19 or below, R82 with Jumbo Hotfix Take 103 or below, R81.20 with Jumbo Hotfix Take 141 or below, R81.10, R81, and R80.40, R80.20.X, R81.10.X, and R82.00.X

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
check pointcheck point remote access vpncert_advisory90%
check pointcheck point mobile accesscert_advisory90%
checkpointgaia_embeddedcve_cpe95%
checkpointquantum_spark_1530cve_cpe95%
checkpointquantum_spark_1550cve_cpe95%

References

  • https://support.checkpoint.com/results/sk/sk185033
  • https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-50751.yaml(exploit, nuclei)

Related News (22 articles)

Tier C
Rapid7 Blog12h ago
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
→ No new info (linked only)
Tier D
BleepingComputer16h ago
Check Point warns of SmartConsole zero-day exploited in attacks
→ No new info (linked only)
Tier C
Rapid7 Blog1d ago
What’s New in Rapid7 Products and Services: Q2 2026 in Review
→ No new info (linked only)
Tier D
BleepingComputer22d ago
ChocoPoc malware delivered via trojanized exploits on GitHub
→ No new info (linked only)
Tier D
The Hacker News38d ago
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
→ No new info (linked only)
Tier B
CERT-FR39d ago
Bulletin d'actualité CERTFR-2026-ACT-026 (15 juin 2026)
→ No new info (linked only)
Tier D
Help Net Security39d ago
Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack
→ No new info (linked only)
Tier D
Help Net Security41d ago
Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)
→ No new info (linked only)
Tier E
Reddit r/netsec41d ago
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs
→ No new info (linked only)
Tier D
SecurityWeek44d ago
Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks
→ No new info (linked only)
Tier B
BSI Advisories44d ago
[NEU] [hoch] Check Point Remote Access VPN und Mobile Access: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
→ No new info (linked only)
Tier D
Infosecurity Magazine44d ago
Check Point Warns Critical Auth Bypass Bug Exploited in the Wild
→ No new info (linked only)
Tier D
Heise Security44d ago
Check Point warnt: Angreifer umgehen VPN-Authentifizierung
→ No new info (linked only)
Tier D
BleepingComputer44d ago
CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day
→ No new info (linked only)
Tier E
Hacker News44d ago
Attackers had month-long head start on patched Check Point VPN zero-day
→ No new info (linked only)
Tier B
CERT-FR45d ago
Multiples vulnérabilités dans les VPN Check Point (09 juin 2026)
→ No new info (linked only)
Tier C
Rapid7 Blog45d ago
Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
→ No new info (linked only)
Tier B
CCCS Canada45d ago
Check Point security advisory (AV26-559)
→ No new info (linked only)
Tier D
The Hacker News45d ago
Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
→ No new info (linked only)
Tier D
BleepingComputer45d ago
Check Point links VPN zero-day attacks to Qilin ransomware gang
→ No new info (linked only)
Tier D
Help Net Security45d ago
Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)
→ No new info (linked only)
Tier C
VulDB45d ago
CVE-2026-50751 | Check Point Quantum Security Gateway/Spark Firewalls IKEv1 Key Exchange improper authentication
→ No new info (linked only)
CVSS 3.19.3 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
fixed version number or null
CWECWE-287
PublishedJun 8, 2026
Last enriched41d agov13
Tags
zero-dayauthentication bypassCVE-2026-50751CISAQilin ransomwareCVE-2026-50752Detection Artefact Generator
Trending Score160🔥
Source articles22
Independent13
Info Completeness12/14
Missing: epss, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (4)

CRITICALCVE-2026-62144
Management Authentication Bypass and Privilege Escalation
Trending: 58
HIGHCVE-2026-62145
Local Privilege Escalation in Gaia Portal
Trending: 45
HIGHCVE-2026-50752
Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1
Trending: 1
HIGHCVE-2026-48131EXP
VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 8, 2026
Added to CISA KEV
Jun 8, 2026
Discovered by ZDM
Jun 8, 2026
Updated: description, severity, activelyExploited
Jun 8, 2026
Updated: exploitAvailable
Jun 8, 2026
Updated: cweIds
Jun 8, 2026
Updated: affectedVersions, patchAvailable, tags
Jun 8, 2026
Updated: cweIds, iocs, tags
Jun 9, 2026
Updated: description, tags
Jun 9, 2026
Updated: description, affectedVersions, tags
Jun 9, 2026
Updated: iocs
Jun 9, 2026
Updated: description
Jun 9, 2026
Updated: description
Jun 9, 2026
Updated: affectedVersions
Jun 9, 2026
Actively Exploited
Jun 10, 2026
Exploit Available
Jun 10, 2026
Patch Available
Jun 10, 2026
Updated: tags
Jun 12, 2026

Version History

v13
Last enriched 41d ago
v13Tier D41d ago

Updated patch availability date to June 8, 2026, and added new tag 'Detection Artefact Generator'.

tags
via Help Net Security
v12Tier B44d ago

Updated affected versions to include R81.10.17 and earlier, R82.00.10 and earlier, R80.40, R81, R81.20 and earlier, R82 and earlier, R82.10 and earlier, and added CVE-2026-50751 and CVE-2026-50752 to tags.

affectedVersions
via CERT-FR
v11Tier D44d ago

Updated description with more technical detail, added CVE-2026-50752 to tags, and confirmed patch availability.

description
via SecurityWeek
v10Tier D44d ago

Updated description with more technical detail, added new IoCs related to the attack infrastructure, and included a new CVE tag for CVE-2026-50752.

description
via Infosecurity Magazine
v9Tier D44d ago

Updated CVSS to 9.3, added new IoCs related to VPS infrastructure and malicious ELF files, and included new tag for CVE-2026-50752 and Qilin ransomware.

iocs
via Heise Security
v8Tier D44d ago

Updated description with technical details about the logic error, added affected software Spark Firewall, and included new IOCs and a new CVE ID for a related vulnerability.

descriptionaffectedVersionstags
via Heise Security
v7Tier D44d ago

Updated description with details on CISA's directive and linked Qilin ransomware activity, and added new tags related to CISA and the ransomware.

descriptiontags
via BleepingComputer
v6Tier E44d ago

Updated description with more technical details, added new CWE, IoCs, and tags related to CVE-2026-50751.

cweIdsiocstags
via Hacker News
v5Tier C45d ago

Updated affected versions to include additional details and added new tags related to zero-day and authentication bypass.

affectedVersionspatchAvailabletags
via Rapid7 Blog
v4Tier D45d ago

Updated description with more technical detail, added CVSS score of 9.3, and included new CWE-295.

cweIds
via The Hacker News
v3Tier B45d ago

Updated product information to include Mobile Access / SSL VPN and confirmed exploit availability.

exploitAvailable
via CCCS Canada
v2Tier C45d ago

Updated severity to CRITICAL, added new product Spark Firewalls, and corrected exploit availability status.

descriptionseverityactivelyExploited
via VulDB
v145d ago

Initial creation