---
schema: 1
kind: vulnerability
title: >
  CVE-2026-50751 — Check Point Security Gateway: IKEv1 VPN authentication bypass, actively
  exploited by a Qilin affiliate
headline: >
  CVE-2026-50751 — Check Point Security Gateway: IKEv1 VPN authentication bypass, actively
  exploited by a Qilin affiliate
summary: >
  Check Point IKEv1 VPN auth bypass (CVE-2026-50751, CVSS 9.3) actively exploited by a Qilin
  affiliate since 7 May — a month before disclosure. Unauthenticated session forgery on Remote
  Access / Mobile Access gateways; NCSC-CH issued an Action-Required advisory and CISA added it to
  KEV (Check Point, 2026-06-08).
discovered_at: "2026-06-09T05:00:02Z"
updated_at: "2026-06-17T05:14:34Z"
event_date: 2026-06-08
run_id: 2026-06-09-40d562df
priority: critical
immediate_action:
  title: Patch Check Point IKEv1 VPN gateways (CVE-2026-50751)
  action: >
    An unauthenticated attacker can forge a Remote Access / Mobile Access VPN session without a
    valid password on gateways running the deprecated IKEv1 key exchange, and the flaw is being
    exploited in the wild by a Qilin ransomware affiliate (exploitation observed since 7 May 2026, a
    month before disclosure). NCSC-CH has issued an Action-Required advisory flagging the CVE as
    actively exploited. Apply hotfix sk185033 now, disable legacy IKEv1 remote-access client
    support, and begin forensic lookback from 7 May for VPN sessions established without a matching
    MFA/password event.
tags:
  - vulnerabilities
  - actively-exploited
  - auth-bypass
  - pre-auth
  - cisa-kev
  - ransomware
  - poc-public
  - patch-available
regions:
  - global
  - switzerland
  - europe
sectors:
  - public-sector
  - finance
  - telco
entities:
  - "actor:qilin"
techniques: []
affected_products: []
cves:
  - id: CVE-2026-50751
    cvss: "9.3"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - poc-public
      - patch-available
  - id: CVE-2026-50752
    cvss: "7.4"
    epss: null
    type: auth-bypass
    vector: zero-click
    auth: pre-auth
    status:
      - exploited
      - cisa-kev
      - patch-available
sources:
  - url: "https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/"
    publisher: Check Point advisory
    role: primary
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12615"
    publisher: NCSC-CH Security Hub
    role: corroborating
  - url: "https://www.rapid7.com/blog/post/etr-critical-check-point-vpn-zero-day-exploited-in-the-wild-cve-2026-50751/"
    publisher: Rapid7
    role: corroborating
  - url: "https://www.helpnetsecurity.com/2026/06/12/cve-2026-50751-poc-exploit/"
    publisher: "Help Net Security, 2026-06-12"
    role: primary
  - url: "https://advisories.ncsc.nl/advisory?id=NCSC-2026-0179"
    publisher: "NCSC-NL advisory NCSC-2026-0179, 2026-06-16"
    role: corroborating
closed_sources: []
evidence:
  - quote: An attacker can bypass user authentication by exploiting a logic flow weakness in the Remote Access and Mobile Access certificate validation and establish a remote access VPN connection without a valid user password
    publisher: Check Point
  - quote: "Current exploitation status: Actively Exploited. Observed exploitation linked to Qilin ransomware affiliate"
    publisher: NCSC-CH Security Hub
verification: multi-source
sourcing_note: null
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification: null
watchlist_hit: false
actions:
  - "**Patch Check Point IKEv1 VPN gateways now (CVE-2026-50751)** — pre-auth authentication bypass under active exploitation by a Qilin affiliate since 7 May; apply hotfix sk185033, disable deprecated IKEv1 remote-access support, and start forensic lookback from 7 May for VPN sessions established without a matching MFA event."
  - "**For Check Point gateways, apply the early-June hotfix and prefer machine-certificate auth or disable IKEv1 legacy mode** now that a CVE-2026-50751 PoC is public (§ 4)."
updates:
  - at: "2026-06-17T05:14:34Z"
    run_id: 2026-06-17-e102009c
    type: update
    summary: >
      UPDATE (originally covered 2026-06-09): NCSC-NL updated its advisory (NCSC-2026-0179, version
      1.0.1) on 2026-06-16 to note that public proof-of-concept code is now available for the Check
      Point Security Gateway IKEv1 authentication bypass (CVE-2026-50751, CVSS 9.3), increasing the
      probability of exploitation …
    fields:
      - actions
      - cves
      - regions
      - sectors
      - sources
      - tags
      - body
    merged_from: 2026-06-17/check-point-ikev1-cve-2026-50751-public-poc-raises-exploitat
migrated_from: briefs/2026-06-09.md
---

Check Point disclosed and patched CVE-2026-50751 (CVSS 9.3) on 8 June 2026 — a logic-flow weakness in certificate validation in the deprecated IKEv1 key exchange affecting Remote Access VPN and Mobile Access deployments. An unauthenticated remote attacker can establish a VPN session without a valid user password; post-authentication activity is still required to reach internal resources ([Check Point, 2026-06-08](https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/)). NCSC-CH issued an Action-Required advisory the same day and links observed exploitation to a Qilin ransomware affiliate ([NCSC-CH, 2026-06-08](https://security-hub.ncsc.admin.ch/#/posts/12615)); CISA added the CVE to its KEV catalog on 8 June. Full technical treatment, exploitation prerequisites and hardening are in § 5 below. The companion CVE-2026-50752 (CVSS 7.4, site-to-site IKEv1 MitM, no observed exploitation) should be patched in the same window.

## Update — 2026-06-17T05:14:34Z

NCSC-NL updated its advisory (NCSC-2026-0179, version 1.0.1) on 2026-06-16 to note that public proof-of-concept code is now available for the Check Point Security Gateway IKEv1 authentication bypass (CVE-2026-50751, CVSS 9.3), increasing the probability of exploitation ([NCSC-NL, 2026-06-16](https://advisories.ncsc.nl/advisory?id=NCSC-2026-0179)).

The flaw lets an unauthenticated client abuse the IKEv1 negotiation to bypass peer-signature verification and impersonate any VPN identity configured for certificate or mixed authentication (username/password-only configurations are not affected); the public PoC follows watchTowr's earlier technical analysis ([Help Net Security, 2026-06-12](https://www.helpnetsecurity.com/2026/06/12/cve-2026-50751-poc-exploit/)). Apply the early-June Check Point hotfix; where feasible disable IKEv1 legacy mode or enforce mandatory machine-certificate authentication, which is not bypassable by this flaw.
