CVE-2026-50752

Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1

Severity
High 7.4
CVSS 3.1
Exploited
Not listed
EPSS
0.050
91.9th percentile
Discovered by
Not disclosed
Published
Jun 8, 2026
Assigned by checkpoint

Description

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.

Weakness: CWE-295

Affected products

Vendor Product Category Matched by
Check Point Quantum Security Gateway Firewall / NGFW cna-assigner
Check Point Quantum Spark Firewall / NGFW cna-assigner
Vendor-reported products (2)
  • checkpoint · Quantum Security Gateway
  • checkpoint · Spark Firewalls

Something wrong here?