LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-50751: Check Point Security Gateway Improper Authentication Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jun 8, 2026
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 11, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-50751 to its Known Exploited Vulnerabilities catalog on Jun 8, 2026, with a federal patch deadline of Jun 11, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Check Point Security Gateway contains an improper authentication vulnerability in IKEv1 key exchange that could allow an unauthenticated remote attacker to bypass user authentication and establish a…

This vulnerability affects Check Point Security Gateway and stems from improper authentication in the IKEv1 key exchange process. An unauthenticated remote attacker can bypass user authentication to establish a remote access VPN connection without supplying a valid password. The issue has been observed in ransomware activity, increasing the chance of unauthorized network entry.

How it works

The weakness is tracked as CWE-287, improper authentication. The flaw resides in the IKEv1 key exchange implementation on the gateway.

Am I affected? How to find it in your systems

Check Point Security Gateway appliances and virtual instances that terminate remote access VPNs are the primary targets. Inventory all perimeter and branch gateways running this software and note any configurations that enable IKEv1.

How to remediate

Apply the vendor update referenced in the official advisory as the primary step. After patching, review and tighten authentication settings for all remote access VPN profiles.

If you can't patch immediately

Follow the mitigations listed in the vendor advisory and any applicable CISA BOD 22-01 guidance for cloud-hosted instances. Segment gateway management and VPN termination interfaces so they are reachable only from trusted management networks.

If your data may have been exposed

Actively exploited vulnerabilities of this type have led to breaches. Run a free exposure scan of your organization's email domains against known breach data to identify any related account exposure.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCheck Point · Security Gateway
WeaknessCWE-287
Added to CISA KEVJun 8, 2026
Federal patch deadlineJun 11, 2026
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities