CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 558

As cited

Copy frozen at (site build).

vulnerabilities

Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)

Check Point released hotfixes on June 8, 2026, for CVE-2026-50751, a CVSS 9.3 authentication bypass vulnerability in IKEv1 VPN code affecting Mobile Access, SSL VPN, Remote Access VPN, and Spark Firewall products. The vulnerability stems from a logic flaw in certificate validation during IKEv1 key exchange that allows clients to bypass authentication checks, and has been exploited in the wild since May 7, 2026, affecting dozens of targeted organizations including at least one incident linked to Qilin ransomware affiliates. Exploitation requires legacy Remote Access clients, IKEv1 protocol enabled, and absence of mandatory machine certificate authentication.

Why it matters: Organizations running affected Check Point versions (R80.20.X through R82.10) with IKEv1 VPN enabled must patch immediately, as this authentication bypass is actively exploited and listed in CISA KEV, creating direct perimeter compromise risk for remote access infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)

Check Point released hotfixes on June 8, 2026 for CVE-2026-50751, a CVSS 9.3 authentication bypass in the IKEv1 code of Mobile Access, SSL virtual private network (VPN), Remote Access VPN, and Spark Firewall products. The vulnerability stems from a logic flaw that allows clients to disable certificate validation during IKEv1 key exchange, and has been exploited in the wild since May 7, 2026 against multiple targeted organizations, including incidents linked to Qilin ransomware affiliates. Exploitation requires that legacy Remote Access clients are accepted, IKEv1 is permitted rather than IKEv2-only, and machine certificate authentication is not mandatory.

Why it matters: Organizations running affected Gaia versions (R80.20.X through R82.10) with IKEv1 enabled and legacy client support active face remote authentication bypass and network intrusion risk, with active exploitation already underway; immediate patching or disabling legacy IKEv1 support is required.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751)

Check Point released hotfixes on June 8, 2026 for CVE-2026-50751, a CVSS 9.3 authentication bypass in the IKEv1 code of Mobile Access, SSL virtual private network (VPN), Remote Access VPN, and Spark Firewall products. The vulnerability stems from a logic flaw that allows clients to disable certificate validation during IKEv1 key exchange, and has been exploited in the wild since May 7, 2026 against multiple targeted organizations, including incidents linked to Qilin ransomware affiliates. Exploitation requires that legacy Remote Access clients are accepted, IKEv1 is permitted rather than IKEv2-only, and machine certificate authentication is not mandatory.

Why it matters: Organizations running affected Gaia versions (R80.20.X through R82.10) with IKEv1 enabled and legacy client support active face remote authentication bypass and network intrusion risk, with active exploitation already underway; immediate patching or disabling legacy IKEv1 support is required.

VendorsCheck Point
Actorsqilin
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary