




















CVE-2026-50751 is a critical vulnerability (CVSS 9.3) in Check Point Remote Access VPN, Mobile Access, and Spark Firewall products using the deprecated IKEv1 key exchange protocol.
Threat Summary
CVE-2026-50751 is a critical vulnerability (CVSS 9.3) in Check Point Remote Access VPN, Mobile Access, and Spark Firewall products using the deprecated IKEv1 key exchange protocol. The flaw is due to a logic error in certificate validation during the IKEv1 handshake that enables unauthenticated attackers to bypass user authentication entirely and initiate VPN connections. Once exploited, attackers gain remote access to internal systems as an authenticated VPN user.
The vulnerability affects numerous Check Point releases—specifically, all remote or mobile access configurations permitting IKEv1; supported versions include R81.20, R82, R82.10, while earlier versions (R81.10, R81, R80.40, R80.20.X) are end-of-support and will not receive patches. The exploit works if IKEv1 is enabled, legacy client support is present, and machine certificates are not required.
The timeline of exploitation began on May 7, 2026, with Check Point’s investigation starting June 4 and public advisory, hotfix, and CVE publication occurring on June 8. On the same day, CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating urgent remediation by all federal civilian executive branch agencies by June 11, 2026. Community forums and technical analyses highlight concern about the extended exploitation window and the criticality of swift mitigation.
Check Point has released emergency hotfixes (SK185033) for supported versions and provided immediate workarounds. No public proof-of-concept exploit is currently available, but active exploitation in the wild is confirmed and likely coordinated through skilled threat actors using VPS infrastructure. Indicators of Compromise (IOCs) and specific attack vectors have been shared. Organizations with affected deployments face a substantial risk of unauthorized access, ransomware, and data theft.
1. Immediate Actions
2. Detection, Monitoring and Incident Response
3. Monitor for anomalous VPN session activity, successful remote connections with IKEv1 but missing expected authentication.
4. Review VPN and firewall logs dating back to May 7, 2026, for suspicious activity.
5. If compromise is suspected, initiate incident response, including credential resets, internal lateral movement checks, and forensic analysis.
References

June 11, 2026
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。