Overview
A critical authentication bypass vulnerability (CVSS 9.3) has been discovered in Check Point Quantum Security Gateway and related products. The flaw resides in the certificate validation logic of the deprecated IKEv1 (Internet Key Exchange version 1) protocol, used by the Remote Access VPN and Mobile Access Software Blades.
An unauthenticated remote attacker can exploit this weakness to bypass user authentication and establish a full Remote Access VPN session without a valid user password, effectively gaining network access as a legitimate VPN user.
Affected Products
-
Check Point Quantum Security Gateway
-
Check Point CloudGuard Network
-
Check Point Quantum Maestro
-
Check Point Quantum Scalable Chassis
-
Check Point Quantum Spark Appliances
Vulnerable versions: R80.20.X, R80.40, R81, R81.10, R81.20, R82, R82.10
(IKEv1 must be enabled with Remote Access VPN or Mobile Access Software Blade)
Impact
Successful exploitation allows an attacker to:
-
Bypass certificate-based authentication in the IKEv1 handshake
-
Establish an authenticated VPN tunnel without valid credentials
-
Gain full network access as if they were a legitimate remote user
-
Move laterally inside the target organization’s internal network
Exploitation in the Wild
This vulnerability has been actively exploited since at least May 7, 2026. A confirmed Qilin ransomware affiliate has been linked to post-compromise activity against targeted organizations globally following exploitation of this flaw. A public proof-of-concept (PoC) has been published.
CISA added CVE-2026-50751 to the Known Exploited Vulnerabilities (KEV) catalog on June 8, 2026, with a remediation due date of June 11, 2026.
Immediate mitigation: Disable IKEv1 on all Security Gateways if Remote Access VPN is not required, or enforce IKEv2 only.

