A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
References
| Link | Resource |
|---|---|
| https://support.checkpoint.com/results/sk/sk185033 | Mitigation Patch Vendor Advisory |
| https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50751 | US Government Resource |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
| AND |
|
Configuration 3 (hide)
| AND |
|
History
09 Jun 2026, 18:30
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:checkpoint:gaia_os:r81.20:take_120:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1550:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_10:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1575:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_119:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_34:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_14:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_41:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_19:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_141:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_2590:-:*:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_2570:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_65:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_2000:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_44:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1900:-:*:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_2530:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_113:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:-:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998002110:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1800:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_43:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_45:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_84:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_25:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998002133:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_89:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_98:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82.10:take_6:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_122:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_92:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_70:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_90:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_111:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_73:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82.10:take_19:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_76:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:-:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998001559:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_43:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_24:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_38:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1590:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_54:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_91:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_12:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1595r:-:*:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1570r:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_101:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:-:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_10:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:build_996004508:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_96:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_53:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:build_996004721:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_2550:-:*:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1555:-:*:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1530:-:*:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1570:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_99:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1535:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_14:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_126:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998002203:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:build_996004892:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1575r:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:*:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_60:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_36:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_105:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:-:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_79:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998001562:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_41:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_8:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:*:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_33:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82.10:-:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_2560:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_26:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:build_996004620:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_115:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_39:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998002112:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:build_996004653:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_1600:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_103:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_127:*:*:*:*:*:* cpe:2.3:h:checkpoint:quantum_spark_2580:-:*:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_18:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r81.20:take_118:*:*:*:*:*:* cpe:2.3:o:checkpoint:gaia_os:r82:take_103:*:*:*:*:*:* |
|
| References | () https://support.checkpoint.com/results/sk/sk185033 - Mitigation, Patch, Vendor Advisory | |
| References | () https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ - Vendor Advisory | |
| References | () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-50751 - US Government Resource | |
| First Time |
Checkpoint quantum Spark 1590
Checkpoint quantum Spark 2570 Checkpoint Checkpoint quantum Spark 2000 Checkpoint quantum Spark 1600 Checkpoint quantum Spark 2590 Checkpoint quantum Spark 1570r Checkpoint quantum Spark 2580 Checkpoint quantum Spark 2530 Checkpoint quantum Spark 1595r Checkpoint quantum Spark 2560 Checkpoint quantum Spark 1530 Checkpoint quantum Spark 1575r Checkpoint quantum Spark 1550 Checkpoint quantum Spark 1575 Checkpoint quantum Spark 1900 Checkpoint quantum Spark 2550 Checkpoint quantum Spark 1570 Checkpoint quantum Spark 1535 Checkpoint gaia Embedded Checkpoint quantum Spark 1555 Checkpoint quantum Spark 1800 Checkpoint gaia Os |
08 Jun 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.3 |
08 Jun 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-08 12:16
Updated : 2026-06-09 18:30
NVD link : CVE-2026-50751
Mitre link : CVE-2026-50751
CVE.ORG link : CVE-2026-50751
JSON object : View
Products Affected
checkpoint
- quantum_spark_1595r
- quantum_spark_1800
- quantum_spark_2590
- quantum_spark_2000
- quantum_spark_2580
- gaia_embedded
- quantum_spark_1575r
- quantum_spark_2560
- quantum_spark_1530
- quantum_spark_1570r
- quantum_spark_1550
- quantum_spark_1555
- quantum_spark_1535
- quantum_spark_1900
- quantum_spark_2570
- quantum_spark_1575
- gaia_os
- quantum_spark_1600
- quantum_spark_2530
- quantum_spark_1570
- quantum_spark_1590
- quantum_spark_2550
CWE
CWE-287
Improper Authentication
