CVE-2026-50751
User Authentication Bypass in VPN Remote Access and Mobile Access
Description
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
In plain language
AI Act nowCVE-2026-50751 is a VPN login-bypass flaw in certain Check Point products that lets attackers get into your VPN without a password—if you use Check Point Quantum Security Gateway, Spark Firewalls, or their Gaia systems for remote/mobile access, treat this as urgent and patch right away.
What to do
- Contact your IT/security person now and ask them to patch Check Point Remote Access and Mobile Access components for CVE-2026-50751 across checkpoint Quantum Security Gateway, checkpoint Spark Firewalls, checkpoint gaia os, and checkpoint gaia embedded.
- Check whether you use IKEv1 for VPN remote/mobile connections, and if so, ask whether it can be disabled or replaced while you patch.
- Review remote access VPN logs for unusual connection attempts or VPN sessions that do not match normal user/password activity, and escalate any suspicious findings.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Ransomware gangs go after EMEA healthcare’s supply chainen-us·Help Net Security· Research Qilin ransomware
- Ransomware in 2026: More groups, more victims, no slowdownen-us·Help Net Security· Research ransomware
- CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wilden·Rapid7 Blog· Exploited Security Management auth-bypass
- New Check Point Zero-Day Vulnerability Exploited in the Wilden-us·SecurityWeek· Exploited Security Management zero-day
- Check Point warns of SmartConsole zero-day exploited in attacksen-us·BleepingComputer· Exploited SmartConsole zero-day
- What’s New in Rapid7 Products and Services: Q2 2026 in Reviewen·Rapid7 Blog· Research
- Малварь ChocoPoC распространяется под видом фальшивых эксплоитовru-ru·Хакер (xakep.ru)· PoC malware
- New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Reposen·The Hacker News· PoC malware
- New ChocoPoC malware targets researchers via trojanized PoC exploitsen-us·BleepingComputer· PoC ChocoPoC malware
- ChocoPoc malware delivered via trojanized exploits on GitHuben-us·BleepingComputer· PoC ChocoPoC malware
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-50751 and every CVE in our database. Create a free account — no credit card required.
Create Free Account