CVE Feed

    Dashboard / CVE / CVE-2026-50751

    CVE-2026-50751

    A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

    Published:Jun 8, 2026
    Last Modified:Jun 10, 2026
    EPS:Jun 8, 2026
    EPSS Score:0.11841
    CVSS Score:9.3

    CISA Notification

    Description

    A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

    Required Action:

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Jun 11, 2026
    92 days ago
    Alert Date
    Jun 8, 2026
    95 days ago

    Affected Products

    Vendor
    Checkpoint
    Product
    Gaia Embedded
    Vendor
    Checkpoint
    Product
    Gaia Os
    Vendor
    Checkpoint
    Product
    Quantum Security Gateway
    Vendor
    Checkpoint
    Product
    Quantum Spark 1530
    Vendor
    Checkpoint
    Product
    Quantum Spark 1535
    Vendor
    Checkpoint
    Product
    Quantum Spark 1550
    Vendor
    Checkpoint
    Product
    Quantum Spark 1555
    Vendor
    Checkpoint
    Product
    Quantum Spark 1570
    Vendor
    Checkpoint
    Product
    Quantum Spark 1570r
    Vendor
    Checkpoint
    Product
    Quantum Spark 1575
    Vendor
    Checkpoint
    Product
    Quantum Spark 1575r
    Vendor
    Checkpoint
    Product
    Quantum Spark 1590
    Vendor
    Checkpoint
    Product
    Quantum Spark 1595r
    Vendor
    Checkpoint
    Product
    Quantum Spark 1600
    Vendor
    Checkpoint
    Product
    Quantum Spark 1800
    Vendor
    Checkpoint
    Product
    Quantum Spark 1900
    Vendor
    Checkpoint
    Product
    Quantum Spark 2000
    Vendor
    Checkpoint
    Product
    Quantum Spark 2530
    Vendor
    Checkpoint
    Product
    Quantum Spark 2550
    Vendor
    Checkpoint
    Product
    Quantum Spark 2560
    Vendor
    Checkpoint
    Product
    Quantum Spark 2570
    Vendor
    Checkpoint
    Product
    Quantum Spark 2580
    Vendor
    Checkpoint
    Product
    Quantum Spark 2590
    Vendor
    Checkpoint
    Product
    Spark Firewalls

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High