A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
| Vendor | Product | Versions |
|---|---|---|
| checkpoint | gaia_os | R82.10 with Jumbo Hotfix Take 19 or below, R82 with Jumbo Hotfix Take 103 or below, R81.20 with Jumbo Hotfix Take 141 or below, R81.10, R81, and R80.40, R80.20.X, R81.10.X, and R82.00.X |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| check point | check point remote access vpn | cert_advisory | 90% |
| check point | check point mobile access | cert_advisory | 90% |
| checkpoint | gaia_embedded | cve_cpe | 95% |
| checkpoint | quantum_spark_1530 | cve_cpe | 95% |
| checkpoint | quantum_spark_1550 | cve_cpe | 95% |
Updated patch availability date to June 8, 2026, and added new tag 'Detection Artefact Generator'.
Updated affected versions to include R81.10.17 and earlier, R82.00.10 and earlier, R80.40, R81, R81.20 and earlier, R82 and earlier, R82.10 and earlier, and added CVE-2026-50751 and CVE-2026-50752 to tags.
Updated description with more technical detail, added CVE-2026-50752 to tags, and confirmed patch availability.
Updated description with more technical detail, added new IoCs related to the attack infrastructure, and included a new CVE tag for CVE-2026-50752.
Updated CVSS to 9.3, added new IoCs related to VPS infrastructure and malicious ELF files, and included new tag for CVE-2026-50752 and Qilin ransomware.
Updated description with technical details about the logic error, added affected software Spark Firewall, and included new IOCs and a new CVE ID for a related vulnerability.
Updated description with details on CISA's directive and linked Qilin ransomware activity, and added new tags related to CISA and the ransomware.
Updated description with more technical details, added new CWE, IoCs, and tags related to CVE-2026-50751.
Updated affected versions to include additional details and added new tags related to zero-day and authentication bypass.
Updated description with more technical detail, added CVSS score of 9.3, and included new CWE-295.
Updated product information to include Mobile Access / SSL VPN and confirmed exploit availability.
Updated severity to CRITICAL, added new product Spark Firewalls, and corrected exploit availability status.
Initial creation