CVE-2026-50751
User Authentication Bypass in VPN Remote Access and Mobile Access
Severity
Critical 9.3
CVSS 3.1
Exploited
Yes — in CISA KEV
Added Jun 8, 2026 · known ransomware use
EPSS
0.838
99.7th percentile
Discovered by
Not disclosed
Published
Jun 8, 2026
Assigned by checkpoint
Description
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Weakness: CWE-287
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Check Point | Quantum Security Gateway | Firewall / NGFW | cna-assigner |
| Check Point | Quantum Spark | Firewall / NGFW | cna-assigner |
Vendor-reported products (2)
- checkpoint · Quantum Security Gateway
- checkpoint · Spark Firewalls