cbcvebase.
CVE-2026-50751
published 2026-06-08

CVE-2026-50751: A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to…

PriorityP1100critical9.3CVSS 3.1
AVNACLPRNUINSCCHILAN
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2026-06-11
Exploited in the wild
EPSS
70.10%
99.3th percentile
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Affected

78 ranges· showing 25
VendorProductVersion rangeFixed in
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded
checkpointgaia_embedded>= r80.20.00 < r81.10.17r81.10.17
checkpointgaia_embedded>= r80.20.00 < r82.00.10r82.00.10
checkpointgaia_os
checkpointgaia_os
checkpointgaia_os
checkpointgaia_os
checkpointgaia_os
checkpointgaia_os
checkpointgaia_os
checkpointgaia_os
checkpointgaia_os
checkpointgaia_os

Detection & IOCsextracted from sources · hover to see the quote

port500/udp
port443/tcp
othershodan:html:"Check Point SSL Network Extender"
bytes
0000000c00000001000000010000000200000001
  • Exploitation requires IKEv1 enabled for remote access on Check Point Security Gateways; monitor for IKEv1 (UDP/500 or TCP/443) authentication attempts against Remote Access VPN or Mobile Access portals where machine certificate authentication is not enforced.
  • Attackers use VPS infrastructure geolocated to the same country as the target organization to blend in; correlate VPN authentication source IPs against known VPS/hosting ASNs for anomalous remote access sessions.
  • Post-exploitation involves downloading ELF binaries from attacker-controlled infrastructure; monitor for outbound HTTP/S connections from VPN gateway hosts to external IPs immediately following a new VPN session establishment.
  • Threat actor C2 uses the Tox protocol; hunt for Tox protocol traffic (UDP-based, characteristic port patterns) originating from compromised VPN gateway or internal hosts post-exploitation.
  • The Nuclei PoC matcher triggers on the string 'BYPASSED' and 'Certificate-auth bypass confirmed' in IKEv1 exchange responses; use these strings to detect active scanning/exploitation attempts in network logs or IDS.
  • Exploitation activity overlaps with Qilin ransomware affiliate TTPs; correlate initial VPN access events with subsequent lateral movement or ransomware staging activity associated with the Qilin/Agenda RaaS group.
  • The exploit abuses a logic flaw in verifyMessagePhase1 certificate signature verification during IKEv1 Phase 1 (Main Mode) exchange; look for IKEv1 MM sessions completing without valid certificate signatures in gateway logs.
  • ·Affected product versions: Security Gateways R82.10 Jumbo Hotfix Take 19 or below, R82 Jumbo Hotfix Take 103 or below, R81.20 Jumbo Hotfix Take 141 or below, R81.10 (EOS), R81 (EOS), R80.40 (EOS); Spark Firewalls R80.20.X (EOS), R81.10.X, R82.00.X.
  • ·A second related vulnerability CVE-2026-50752 (CVSS 7.4) exists for AitM attacks on site-to-site VPN connections via the same IKEv1 certificate validation code path, but has no confirmed in-the-wild exploitation as of disclosure.
  • ·Post-authentication activity is still required to access internal resources or escalate privileges after the initial authentication bypass; the bypass alone does not grant full internal network access.

CVSS provenance

nvdv3.19.3CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
vulncheck9.3CRITICAL
cisa9.3CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.