CVE-2026-50751: Check Point Security Gateway Improper Authentication
Check Point Security Gateway Improper Authentication Vulnerability. Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
- CISA KEV-listed (remediation due 2026-06-11)
- used in ransomware campaigns
- EPSS 82.6% (99.6% percentile)
- CVSS 9.3 critical
Related briefings
- Hackers exploit a critical Check Point flaw to hijack management servers 2026-07-25
- CISA warns SimpleHelp remote-support bug is under active attack 2026-06-30
- Node.js fixes TLS flaws that let attackers impersonate trusted servers 2026-06-20
- Hackers spray Fortinet and Sophos firewalls to steal corporate logins 2026-06-20
- Critical Ivanti Sentry flaw exploited in the wild after public exploit release 2026-06-12