Check Point Security Gateway Improper Authentication Vulnerability
Critical CVSS 9.3 Listed in CISA KEV
Summary
Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- Check Point:Security Gateway
- :
- :
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2026-50751 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ reference
- https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM. reference
- https://support.checkpoint.com/results/sk/sk185033 Mitigation
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50751 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD