Knox CVE Database
/
CVE-2026-50751
Critical
9.3
Ransomware use

CVE-2026-50751: Check Point Security Gateway Improper Authentication Vulnerability

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Added to the CISA KEV catalog:
June 8, 2026

Overview

Check Point Security Gateway contains an authentication bypass in the deprecated IKEv1 key exchange protocol, affecting Remote Access VPN and Mobile Access deployments across a wide range of Quantum Security Gateway, Spark Firewall, Gaia OS, and Gaia Embedded versions. By exploiting a logic flaw in certificate validation, an unauthenticated remote attacker can complete the VPN handshake and obtain a valid session without supplying a correct user password. This vulnerability is actively exploited in the wild and has been linked to Qilin ransomware activity.

Vulnerability details

Affected vendor
Check Point
Affected product
Security Gateway
Weakness type (CWE)
CWE-287

The flaw is classified as CWE-287 (Improper Authentication): the authentication logic governing IKEv1 certificate validation can be satisfied without the credential it is supposed to require. IKEv1 is a deprecated key exchange protocol that Check Point still supports on affected gateway versions. During the authentication phase, a logic error in how the gateway validates the client certificate allows the handshake to complete successfully even when the user has not provided a valid password, granting the attacker an authenticated VPN session.


An attacker with network access to UDP ports 500 or 4500 on an affected gateway initiates an IKEv1 Remote Access or Mobile Access VPN exchange and supplies crafted or manipulated certificate material that exploits the validation logic flaw. No valid password is required. The result is an authenticated VPN tunnel. Additional post-exploitation steps are needed to reach internal resources or escalate privileges, but the initial foothold is gained entirely without credentials. Check Point Research has confirmed active exploitation, with at least one incident involving confirmed Qilin ransomware post-compromise activity.

Severity and impact

9.3
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality impact
High
Integrity impact
Low
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Known

Detection and monitoring

  • Review VPN authentication logs for IKEv1 Remote Access or Mobile Access sessions that completed successfully with no corresponding password authentication event, indicating the certificate validation path was traversed without credential verification.
  • Correlate successful VPN session establishment events against your gateway's configured authentication methods: any IKEv1 session recorded as authenticated where the identity backend (LDAP, RADIUS, or local user store) shows no matching authentication request is a strong indicator of bypass exploitation.
  • Check firewall and IKE daemon logs for inbound IKEv1 negotiation traffic originating from the specific IP addresses published in Check Point's advisory IOC list. Match the listed addresses themselves, not their hosting providers' wider ranges, which would fire on unrelated customers.

Remediation

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Federal (FCEB) remediation due date
June 11, 2026

Additional hardening

  • Apply the vendor-released hotfix for your release line: Quantum Security Gateway R82.10 requires Jumbo Hotfix Take 20 or later, R82 requires Take 104 or later, and R81.20 requires Take 142 or later; consult the vendor advisory in References for R81.10, R81, R80.40, and Spark Firewall boundaries.
  • Disable IKEv1 on all Security Gateways where it is not operationally required. IKEv1 is deprecated; migrating Remote Access and Mobile Access configurations to IKEv2 eliminates the vulnerable code path entirely.
  • Restrict UDP 500 and 4500 access to the gateway to known, authorized client IP ranges using perimeter ACLs or upstream firewall rules, reducing the attack surface to authenticated network positions rather than the open internet.
  • Block or null-route the published actor IP indicators at the perimeter and review VPN session logs from May 7, 2026 onward, the earliest observed exploitation date identified by Check Point Research, for signs of unauthorized session establishment.

Key dates

Published (NVD)
June 8, 2026
Added to CISA KEV
June 8, 2026
Remediation deadline
June 11, 2026
Last updated
August 4, 2026

References

Frequently asked questions

Does CVE-2026-50751 affect my FedRAMP authorization?

If Check Point Security Gateway runs inside your authorization boundary, yes. CVE-2026-50751 appears on CISA's Known Exploited Vulnerabilities (KEV) catalog, and its June 11, 2026 remediation deadline has already passed. For a FedRAMP-authorized service, an unpatched KEV is an assessor finding. An overdue one is a finding your assessor and sponsoring agency can see right now. Your options are to remediate it immediately or formally document the mitigation and the delay.

How does Knox help me handle CVE-2026-50751?

Knox does not patch your software. Remediating Check Point Security Gateway is your responsibility under the FedRAMP shared-responsibility model. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage that document the fix for your next assessment. Applying the patch is yours to do; managing your compliance posture while you do it is not something you have to handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on a continuous basis. For a CVE like CVE-2026-50751, that means exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving you a shorter window between disclosure and awareness.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60-80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

CVE-2026-50751's remediation deadline of June 11, 2026 has passed. What happens now?

If CVE-2026-50751 remains unremediated, it is already a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Closing it out now and documenting why the deadline was missed is what keeps your authorization intact and the agency relationship on solid ground.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.