CVE-2026-50751 is an authentication bypass vulnerability affecting Check Point Security Gateway Remote Access VPN and Mobile Access services. The flaw exists in deprecated IKEv1 Remote Access and Mobile Access certificate validation logic and can allow a remote attacker to establish a VPN session without supplying a valid password. Check Point has confirmed active exploitation in the wild and reported a limited number of targeted organizations globally, including at least one post-compromise case linked to a Qilin ransomware affiliate.
The vulnerability affects the authentication process used by deprecated IKEv1-based Remote Access VPN deployments.
A successful attacker can:
Check Point notes that successful exploitation grants VPN access but additional actions are required before an attacker can access internal resources or elevate privileges.
The vendor reports exploitation activity beginning on May 7, 2026, with activity increasing in early June and prompting public disclosure and remediation guidance.
A NodeZero Rapid Response test has been developed to safely validate whether this authentication bypass can be exploited in your environment. The test executes real attack techniques without causing damage, giving teams immediate clarity on exposure.
| Indicator | Type | Description |
| 45.77.149.152 | IP Address | Suspicious infrastructure identified by Check Point |
| 209.182.225.136 | IP Address | Suspicious infrastructure identified by Check Point |
| 38.60.157.139 | IP Address | Suspicious infrastructure identified by Check Point |
| 162.33.177.101 | IP Address | Suspicious infrastructure identified by Check Point |
| 45.76.26.42 | IP Address | Suspicious infrastructure identified by Check Point |
| 144.208.127.155 | IP Address | Suspicious infrastructure identified by Check Point |
| 38.54.88.201 | IP Address | Suspicious infrastructure identified by Check Point |
| 38.54.107.167 | IP Address | Suspicious infrastructure identified by Check Point |
| 66.42.99.200 | IP Address | Suspicious infrastructure identified by Check Point |
| 52fda5c1b9704544f32ee98d9060e689 | File Hash | Associated with observed malicious activity |
| 51d39aa39478beeac94f2d12f682ecce | File Hash | Associated with observed malicious activity |
Check Point also reported additional malicious infrastructure identified between June 9 and June 11, 2026.
Check Point lists the following as affected: