CVE-2026-50751: CWE-287: Improper Authentication. in checkpoint Quantum Security Gateway
A security update addresses multiple vulnerabilities discovered during routine security review, including authentication bypass issues affecting management products. One vulnerability (CVE-2026-16232) has been exploited in the wild against a limited number of customers with specific configurations where Management is exposed directly to the internet without IP restrictions. The affected systems include Security Management and Multi-Domain Management across multiple versions. Two additional vulnerabilities address authentication bypass with privilege escalation and local privilege escalation in GaiaOS WebUI. All impacted customers have been notified, and Smart-1 Cloud customers are already protected. Indicators of compromise include six IP addresses associated with the exploitation activity. Installation of the latest Jumbo hotfix is recommended along with implementation of security best practices.
AI Analysis
Technical Summary
CVE-2026-50751 is a critical vulnerability in Check Point Quantum Security Gateway's Remote Access and Mobile Access components that use the deprecated IKEv1 key exchange protocol. The flaw is a logic flow weakness in certificate validation that enables an unauthenticated remote attacker to bypass user authentication and establish a VPN connection without a valid password. This vulnerability affects versions 81.10, all versions up to 81.20, and up to 82.10. The CVSS v3.1 base score is 9.3 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N), reflecting network attack vector, low attack complexity, no privileges required, no user interaction, scope changed, high confidentiality impact, low integrity impact, and no availability impact. No official patch or remediation guidance has been provided by Check Point as of the publication date.
Potential Impact
An unauthenticated remote attacker can bypass authentication mechanisms in the affected Check Point Quantum Security Gateway versions and establish a VPN connection without valid credentials. This compromises confidentiality by potentially exposing sensitive network resources accessible via the VPN. The integrity impact is low, and availability is not affected. The vulnerability affects the deprecated IKEv1 key exchange implementation in Remote Access and Mobile Access certificate validation.
Mitigation Recommendations
No official patch or remediation guidance is currently available from the vendor. Users should monitor vendor advisories for updates. As this vulnerability affects the deprecated IKEv1 key exchange, disabling or avoiding use of IKEv1 and migrating to supported protocols such as IKEv2 may reduce exposure. Network administrators should consider restricting VPN access and monitoring for unauthorized connections until a fix is provided.
Indicators of Compromise
- cve: CVE-2026-50751
- cve: CVE-2026-16232
- cve: CVE-2026-62144
- cve: CVE-2026-62145
- ip: 139.28.37.250
- ip: 151.241.99.207
- ip: 151.241.99.233
- ip: 158.62.198.182
CVE-2026-50751: CWE-287: Improper Authentication. in checkpoint Quantum Security Gateway
Description
A security update addresses multiple vulnerabilities discovered during routine security review, including authentication bypass issues affecting management products. One vulnerability (CVE-2026-16232) has been exploited in the wild against a limited number of customers with specific configurations where Management is exposed directly to the internet without IP restrictions. The affected systems include Security Management and Multi-Domain Management across multiple versions. Two additional vulnerabilities address authentication bypass with privilege escalation and local privilege escalation in GaiaOS WebUI. All impacted customers have been notified, and Smart-1 Cloud customers are already protected. Indicators of compromise include six IP addresses associated with the exploitation activity. Installation of the latest Jumbo hotfix is recommended along with implementation of security best practices.
CVSS v3.1
Score 9.3critical
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-50751 is a critical vulnerability in Check Point Quantum Security Gateway's Remote Access and Mobile Access components that use the deprecated IKEv1 key exchange protocol. The flaw is a logic flow weakness in certificate validation that enables an unauthenticated remote attacker to bypass user authentication and establish a VPN connection without a valid password. This vulnerability affects versions 81.10, all versions up to 81.20, and up to 82.10. The CVSS v3.1 base score is 9.3 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N), reflecting network attack vector, low attack complexity, no privileges required, no user interaction, scope changed, high confidentiality impact, low integrity impact, and no availability impact. No official patch or remediation guidance has been provided by Check Point as of the publication date.
Potential Impact
An unauthenticated remote attacker can bypass authentication mechanisms in the affected Check Point Quantum Security Gateway versions and establish a VPN connection without valid credentials. This compromises confidentiality by potentially exposing sensitive network resources accessible via the VPN. The integrity impact is low, and availability is not affected. The vulnerability affects the deprecated IKEv1 key exchange implementation in Remote Access and Mobile Access certificate validation.
Mitigation Recommendations
No official patch or remediation guidance is currently available from the vendor. Users should monitor vendor advisories for updates. As this vulnerability affects the deprecated IKEv1 key exchange, disabling or avoiding use of IKEv1 and migrating to supported protocols such as IKEv2 may reduce exposure. Network administrators should consider restricting VPN access and monitoring for unauthorized connections until a fix is provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- checkpoint
- Date Reserved
- 2026-06-07T09:42:08.251Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Indicators of Compromise
Cve
| Value | Description | Copy |
|---|---|---|
cveCVE-2026-50751 | — | |
cveCVE-2026-16232 | — | |
cveCVE-2026-62144 | — | |
cveCVE-2026-62145 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip139.28.37.250 | — | |
ip151.241.99.207 | — | |
ip151.241.99.233 | — | |
ip158.62.198.182 | — |
Threat ID: 6a26a89fe29bf47b50de2528
Added to database: 06/08/2026, 11:33:51 UTC
Last enriched: 07/24/2026, 20:52:02 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 114
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.