CVE-2026-50751

medium Check Point ⚠️ CISA KEV — Exploited in the Wild
EPSS Score
82.6%
Exploitation probability in 30 days
Top 0% most likely to be exploited
Published: June 8, 2026 (90 days ago)
Last Modified: August 4, 2026
Vendor: Check Point
Source: MITRE

⚠️ CISA Known Exploited Vulnerability

Added to KEV: 2026-06-08
Remediation Due: 2026-06-11 (⚠ 87d overdue)
Ransomware Campaign: Known

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CWE

CWE-287

Affected Products

checkpoint Quantum Security Gatewaycheckpoint Spark Firewalls

References