CVE-2026-50752
Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1
Severity
High 7.4
CVSS 3.1
Exploited
Not listed
EPSS
0.050
91.9th percentile
Discovered by
Not disclosed
Published
Jun 8, 2026
Assigned by checkpoint
Description
A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.
Weakness: CWE-295
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Check Point | Quantum Security Gateway | Firewall / NGFW | cna-assigner |
| Check Point | Quantum Spark | Firewall / NGFW | cna-assigner |
Vendor-reported products (2)
- checkpoint · Quantum Security Gateway
- checkpoint · Spark Firewalls