Check Point Remote Access VPN and Mobile Access (IKEv1)

CVE-2026-50751: Check Point VPN login bypass in legacy IKEv1, used by Qilin affiliate

A logic flaw in IKEv1 certificate validation lets an unauthenticated attacker open a Remote Access VPN session without a valid password (CVSS 9.3). Exploited since May 7, 2026 against a few dozen organizations, including a Qilin ransomware affiliate case.

Published Updated

ExploitedYes, in CISA KEVAdded 8 Jun 2026
Ransomware useKnownPer CISA
SeverityCRITICALCVSS 3.1 9.3
EPSS85%Chance of exploitation in 30 days
Public exploitNot known
FixAvailable

Affected and fixed versions

Product / branchFixed in
Quantum Security Gateway R82.10Jumbo Hotfix Take 20 or later
Quantum Security Gateway R82Jumbo Hotfix Take 104 or later
Quantum Security Gateway R81.20Jumbo Hotfix Take 142 or later
Quantum Security Gateway R81.10, R81, R80.40 (end of support)No fix. Upgrade to a supported, patched version
Spark Firewalls R80.20.X, R81.10.X, R82.00.XSee Check Point sk185033

Always confirm against the vendor advisory, which lists every fixed hotfix.

What it is

Check Point gateways can still negotiate the old IKEv1 key exchange for Remote Access and Mobile Access VPN. On vulnerable builds, the certificate check in that path can be skipped. An unauthenticated attacker can open a VPN session without a valid password.

watchTowr traced the cause to the iked daemon. A “VPNExtFeatures” Vendor ID payload sent by the client writes four attacker-chosen bytes into the gateway’s state flags. Those flags decide whether the client’s proof of private key is checked, so the client controls whether it is authenticated. The gateway accepted a self-signed certificate with a garbage signature, as long as the subject name matched a real Remote Access user.

The bypass only gets the attacker onto the VPN. Check Point says further post-authentication activity is needed to reach internal resources. Even so, this is a direct path into the network.

It is exploited. Check Point Research saw attacks from May 7, 2026, a month before the fix, against a few dozen targeted organizations. One case involved a Qilin ransomware affiliate (medium confidence). CISA lists it in KEV, with known ransomware use.

Check Point also fixed CVE-2026-50752, a related IKEv1 certificate flaw (CVSS 7.4) that could allow man-in-the-middle attacks on site-to-site VPN. Check Point has not seen it exploited. Its advisory is sk185035.

Am I affected?

You’re exposed when all of these are true (Arctic Wolf, watchTowr):

  1. The gateway runs an affected version (see the table above).
  2. Remote Access or Mobile Access VPN is enabled and IKEv1 is allowed, not IKEv2 only.
  3. The gateway accepts legacy Remote Access clients.
  4. Machine certificate authentication is not required.

watchTowr confirmed the bypass in Certificate, Certificate with enrollment and Mixed authentication modes. Plain username and password mode could not be bypassed this way, because the password step still runs. The attack works on 500/UDP and 4500/UDP, and on 443/TCP through the Visitor Mode fallback.

Check the gateway’s Remote Access community and VPN settings in SmartConsole for IKEv1, legacy client support and machine certificate requirements. I could not open Check Point’s advisory, so the exact menu paths are in sk185033.

Not affected by this CVE: gateways that accept IKEv2 only, or that require machine certificates. The site-to-site issue is a separate CVE.

What to do

  1. Install the hotfix from sk185033. Fixed builds are R82.10 Jumbo Hotfix Take 20 or later, R82 Take 104 or later and R81.20 Take 142 or later. Spark Firewalls have their own fix in the same advisory.
  2. Upgrade end-of-support gateways. R81.10, R81, R80.40 and R80.20.X get no fix. Move to a supported, patched release.
  3. If you can’t patch tonight, change the VPN configuration:
    • Switch Remote Access and Mobile Access to IKEv2 only. Clients that can’t use IKEv2 will stop connecting.
    • Block legacy Remote Access clients.
    • Require machine certificate authentication. Arctic Wolf says this breaks the bypass even with IKEv1 on.
    • Check Point’s community also offers mitigation scripts. Test them first.
  4. Hunt back to May 7, 2026 (see Detection). Block the listed IP addresses at the perimeter.
  5. If you find a suspect login, treat it as an intrusion. Terminate the VPN sessions, reset the affected users’ credentials, check lateral movement and engage incident response.

CISA’s deadline for US federal agencies was June 11, 2026.

Detection

Search VPN and gateway logs from May 7, 2026 onward.

  • Successful Remote Access logins over IKEv1 with a user that did not really authenticate. watchTowr’s test gateway logged verify_peer_auth: vendorid=0 .. not a Check Point peer, then IkeSAFromState: User <name> saved. A patched gateway logged verifyMessagePhase1: Authentication failure with hybrid.
  • On the network, an IKE peer whose only Vendor ID is “VPNExtFeatures” (the 16-byte value 3c f1 87 b2 47 40 29 ea 46 ac 7f d0 ea f2 89 f5 followed by four bytes) with no other Check Point Vendor ID. watchTowr calls this a strong signal. Its detection artefact generator is on GitHub as watchtowrlabs/watchTowr-vs-Check-Point-CVE-2026-50751.
  • Connections from the IP addresses in the indicator list, and VPN sessions from VPS hosting ranges your users don’t use.
  • Check Point links the actor’s post-access activity to Qilin Linux ransomware binaries and ELF downloads from attacker infrastructure. It also saw possible use of the Tox protocol. Search endpoints for the two MD5 hashes.

Indicators of compromise

The addresses are mostly rented VPS servers (Check Point names Kaupo Cloud HK, Shock Hosting and Vultr). Use them to search past logs from May 7, 2026, not as your only defense.

The .txt list has one IP per line and a fixed address, so a firewall can pull it as an External Dynamic List: https://patchtonight.com/iocs/CVE-2026-50751.txt

IndicatorTypeReported by
45.77.149[.]152IPCheck Point Research, Arctic Wolf
209.182.225[.]136IPCheck Point Research, Arctic Wolf
38.60.157[.]139IPCheck Point Research, Arctic Wolf
162.33.177[.]101IPCheck Point Research, Arctic Wolf
45.76.26[.]42IPCheck Point Research, Arctic Wolf
144.208.127[.]155IPCheck Point Research, Arctic Wolf
38.54.88[.]201IPCheck Point Research, Arctic Wolf
38.54.107[.]167IPCheck Point Research, Arctic Wolf
66.42.99[.]200IPCheck Point Research, Arctic Wolf
45.63.104[.]106IPAdded June 9Check Point Research
45.61.136[.]173IPAdded June 9Check Point Research
146.71.81[.]184IPAdded June 10Check Point Research
208.123.119[.]167IPAdded June 11Check Point Research
64.176.228[.]109IPAdded June 11Check Point Research
158.247.195[.]147IPAdded June 11Check Point Research
144.208.127[.]134IPAdded June 11Check Point Research
52fda5c1b9704544f32ee98d9060e689SHA-256MD5Check Point Research
51d39aa39478beeac94f2d12f682ecceSHA-256MD5Check Point Research

Sources

Page changelog

  • Full analysis published.

KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.