# CVE-2026-50751

## Summary

- **CVE ID:** CVE-2026-50751
- **Severity:** CRITICAL
- **CVSS Score:** 9.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N)
- **CWE:** CWE-287
- **Published:** Jun 8, 2026
- **Last Modified:** Aug 4, 2026

## Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

## Affected Products

- checkpoint — Quantum Security Gateway (R82.10 with Jumbo Hotfix Take 19 or below)
- checkpoint — Quantum Security Gateway (R82 with Jumbo Hotfix Take 103 or below)
- checkpoint — Quantum Security Gateway (R81.20 with Jumbo Hotfix Take 141 or below)
- checkpoint — Quantum Security Gateway (R81.10, R81, and R80.40)
- checkpoint — Spark Firewalls (R80.20.X, R81.10.X, and R82.00.X)

## References

- [CNA](https://support.checkpoint.com/results/sk/sk185033)
- [CISA-ADP](https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/)
- [CISA-ADP](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50751)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 83.77%
- **EPSS Percentile:** 99.7

## Known Exploited Vulnerabilities (KEV)

- **Date Added:** Jun 8, 2026
- **Due Date:** Jun 11, 2026

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._