Vulnerability Description
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Checkpoint | Gaia Os | >= r80.40, < r81.20 |
| Checkpoint | Gaia Embedded | >= r80.20.00, < r81.10.17 |
| Checkpoint | Quantum Spark 1530 | - |
| Checkpoint | Quantum Spark 1550 | - |
| Checkpoint | Quantum Spark 1570 | - |
| Checkpoint | Quantum Spark 1570R | - |
| Checkpoint | Quantum Spark 1590 | - |
| Checkpoint | Quantum Spark 1595R | - |
| Checkpoint | Quantum Spark 1600 | - |
| Checkpoint | Quantum Spark 1800 | - |
| Checkpoint | Quantum Spark 1900 | - |
| Checkpoint | Quantum Spark 2000 | - |
| Checkpoint | Quantum Spark 1535 | - |
| Checkpoint | Quantum Spark 1555 | - |
| Checkpoint | Quantum Spark 1575 | - |
| Checkpoint | Quantum Spark 1575R | - |
| Checkpoint | Quantum Spark 2530 | - |
| Checkpoint | Quantum Spark 2550 | - |
| Checkpoint | Quantum Spark 2560 | - |
| Checkpoint | Quantum Spark 2570 | - |
Related Weaknesses (CWE)
References
- https://support.checkpoint.com/results/sk/sk185033MitigationPatchVendor Advisory
- https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-US Government Resource
FAQ
What is CVE-2026-50751?
CVE-2026-50751 is a vulnerability with a CVSS score of 9.3 (CRITICAL). A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a...
How severe is CVE-2026-50751?
CVE-2026-50751 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-50751?
Check the references section above for vendor advisories and patch information. Affected products include: Checkpoint Gaia Os, Checkpoint Gaia Embedded, Checkpoint Quantum Spark 1530, Checkpoint Quantum Spark 1550, Checkpoint Quantum Spark 1570.