Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4357 articles · 196326 vulns · 36/41 feeds (7d)
← Back to list
9.3
CVE-2026-50751KEVEXPLOITEDPATCHED
checkpoint · gaia_os

User Authentication Bypass in VPN Remote Access and Mobile Access

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Affected Products

VendorProductVersions
checkpointgaia_osR82.10 with Jumbo Hotfix Take 19 or below, R82 with Jumbo Hotfix Take 103 or below, R81.20 with Jumbo Hotfix Take 141 or below, R81.10, R81, and R80.40, R80.20.X, R81.10.X, and R82.00.X

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
check pointcheck point remote access vpncert_advisory90%
check pointcheck point mobile accesscert_advisory90%
checkpointgaia_embeddedcve_cpe95%
checkpointquantum_spark_1530cve_cpe95%
checkpointquantum_spark_1550cve_cpe95%

References

  • https://support.checkpoint.com/results/sk/sk185033

Related News (23 articles)

Tier D
Heise Security19d ago
Check Point: Angreifer können Security-Management-Server übernehmen
→ No new info (linked only)
Tier C
Rapid7 Blog31d ago
CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wild
→ No new info (linked only)
Tier D
BleepingComputer31d ago
Check Point warns of SmartConsole zero-day exploited in attacks
→ No new info (linked only)
Tier C
Rapid7 Blog32d ago
What’s New in Rapid7 Products and Services: Q2 2026 in Review
→ No new info (linked only)
Tier D
BleepingComputer53d ago
ChocoPoc malware delivered via trojanized exploits on GitHub
→ No new info (linked only)
Tier D
The Hacker News69d ago
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
→ No new info (linked only)
Tier B
CERT-FR70d ago
Bulletin d'actualité CERTFR-2026-ACT-026 (15 juin 2026)
→ No new info (linked only)
Tier D
Help Net Security70d ago
Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack
→ No new info (linked only)
Tier D
Help Net Security72d ago
Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751)
→ No new info (linked only)
Tier E
Reddit r/netsec72d ago
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs
→ No new info (linked only)
Tier D
SecurityWeek75d ago
Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks
→ No new info (linked only)
Tier B
BSI Advisories75d ago
[NEU] [hoch] Check Point Remote Access VPN und Mobile Access: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungen
→ No new info (linked only)
Tier D
Infosecurity Magazine75d ago
Check Point Warns Critical Auth Bypass Bug Exploited in the Wild
→ No new info (linked only)
Tier D
Heise Security75d ago
Check Point warnt: Angreifer umgehen VPN-Authentifizierung
→ No new info (linked only)
Tier D
BleepingComputer75d ago
CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day
→ No new info (linked only)
Tier E
Hacker News76d ago
Attackers had month-long head start on patched Check Point VPN zero-day
→ No new info (linked only)
Tier B
CERT-FR76d ago
Multiples vulnérabilités dans les VPN Check Point (09 juin 2026)
→ No new info (linked only)
Tier C
Rapid7 Blog76d ago
Critical Check Point VPN Zero-Day Exploited in the Wild (CVE-2026-50751)
→ No new info (linked only)
Tier B
CCCS Canada76d ago
Check Point security advisory (AV26-559)
→ No new info (linked only)
Tier D
The Hacker News76d ago
Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups
→ No new info (linked only)
Tier D
BleepingComputer76d ago
Check Point links VPN zero-day attacks to Qilin ransomware gang
→ No new info (linked only)
Tier D
Help Net Security76d ago
Qilin ransomware affiliate exploited Check Point VPN zero-day (CVE-2026-50751)
→ No new info (linked only)
Tier C
VulDB76d ago
CVE-2026-50751 | Check Point Quantum Security Gateway/Spark Firewalls IKEv1 Key Exchange improper authentication
→ No new info (linked only)
CVSS 3.19.3 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
fixed version number or null
CWECWE-287
PublishedJun 8, 2026
Last enriched72d agov13
Tags
zero-dayauthentication bypassCVE-2026-50751CISAQilin ransomwareCVE-2026-50752Detection Artefact Generator
Trending Score11
Source articles23
Independent13
Info Completeness12/14
Missing: epss, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-18574
Authentication Bypass in Check Point Security Management Server
Trending: 12
NONECVE-2026-16232EXP
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Trending: 3
CRITICALCVE-2026-62144
Management Authentication Bypass and Privilege Escalation
Trending: 3
HIGHCVE-2026-62145
Local Privilege Escalation in Gaia Portal
Trending: 2
HIGHCVE-2026-50752
Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 8, 2026
Added to CISA KEV
Jun 8, 2026
Discovered by ZDM
Jun 8, 2026
Updated: description, severity, activelyExploited
Jun 8, 2026
Updated: exploitAvailable
Jun 8, 2026
Updated: cweIds
Jun 8, 2026
Updated: affectedVersions, patchAvailable, tags
Jun 8, 2026
Updated: cweIds, iocs, tags
Jun 9, 2026
Updated: description, tags
Jun 9, 2026
Updated: description, affectedVersions, tags
Jun 9, 2026
Updated: iocs
Jun 9, 2026
Updated: description
Jun 9, 2026
Updated: description
Jun 9, 2026
Updated: affectedVersions
Jun 9, 2026
Updated: tags
Jun 12, 2026
Actively Exploited
Aug 4, 2026
Exploit Available
Aug 4, 2026
Patch Available
Aug 4, 2026

Version History

v13
Last enriched 72d ago
v13Tier D72d ago

Updated patch availability date to June 8, 2026, and added new tag 'Detection Artefact Generator'.

tags
via Help Net Security
v12Tier B75d ago

Updated affected versions to include R81.10.17 and earlier, R82.00.10 and earlier, R80.40, R81, R81.20 and earlier, R82 and earlier, R82.10 and earlier, and added CVE-2026-50751 and CVE-2026-50752 to tags.

affectedVersions
via CERT-FR
v11Tier D75d ago

Updated description with more technical detail, added CVE-2026-50752 to tags, and confirmed patch availability.

description
via SecurityWeek
v10Tier D75d ago

Updated description with more technical detail, added new IoCs related to the attack infrastructure, and included a new CVE tag for CVE-2026-50752.

description
via Infosecurity Magazine
v9Tier D75d ago

Updated CVSS to 9.3, added new IoCs related to VPS infrastructure and malicious ELF files, and included new tag for CVE-2026-50752 and Qilin ransomware.

iocs
via Heise Security
v8Tier D75d ago

Updated description with technical details about the logic error, added affected software Spark Firewall, and included new IOCs and a new CVE ID for a related vulnerability.

descriptionaffectedVersionstags
via Heise Security
v7Tier D75d ago

Updated description with details on CISA's directive and linked Qilin ransomware activity, and added new tags related to CISA and the ransomware.

descriptiontags
via BleepingComputer
v6Tier E75d ago

Updated description with more technical details, added new CWE, IoCs, and tags related to CVE-2026-50751.

cweIdsiocstags
via Hacker News
v5Tier C76d ago

Updated affected versions to include additional details and added new tags related to zero-day and authentication bypass.

affectedVersionspatchAvailabletags
via Rapid7 Blog
v4Tier D76d ago

Updated description with more technical detail, added CVSS score of 9.3, and included new CWE-295.

cweIds
via The Hacker News
v3Tier B76d ago

Updated product information to include Mobile Access / SSL VPN and confirmed exploit availability.

exploitAvailable
via CCCS Canada
v2Tier C76d ago

Updated severity to CRITICAL, added new product Spark Firewalls, and corrected exploit availability status.

descriptionseverityactivelyExploited
via VulDB
v176d ago

Initial creation