Vulnerability Intelligence Report
User Authentication Bypass in VPN Remote Access and Mobile Access
CVE-2026-50751
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
Authentication Bypass
CVSS Base Score
9.3
CRITICAL
Exploitability:3.9
Impact Score:4.8
EPSS Probability:82.55%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-287 ↗CWE-287: Improper Authentication.
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| checkpoint | Quantum Security Gateway | R82.10 with Jumbo Hotfix Take 19 or below (affected), R82 with Jumbo Hotfix Take 103 or below (affected), R81.20 with Jumbo Hotfix Take 141 or below (affected), R81.10, R81, and R80.40 (affected) |
| checkpoint | Spark Firewalls | R80.20.X, R81.10.X, and R82.00.X (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
82.554%
GitHub Advisory
Vulnerability Class
Authentication Bypass
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Check Point Software Ltd. · Vendor · Israel |
| Reserved | 2026-06-07T09:42:08 |
| Published | 2026-06-08T11:07:15 |
| Last Updated | 2026-08-04T03:56:11 |
Community Chatter & Buzz