🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Check Point Remote Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) | MSSP Advisory

Critical🔴 KEV ALERTConfirmed
DateJune 12, 2026
CVECVE-2026-50751
CVSS Score9.3
Affectedgaia_os, gaia_embedded, quantum_spark_1530
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
Check Point released hotfixes on June 8, 2026 for CVE-2026-50751, a CVSS 9.3 authentication bypass in the IKEv1 code path of their Remote Access VPN, Mobile Access, and Spark Firewall products across Gaia versions R80.20.X through R82.10. The flaw allows an attacker to send a crafted VPNExtFeatures Vendor ID payload that sets a bitmask flag telling the gateway to skip certificate signature verification entirely, meaning a self-signed cert and random garbage bytes are enough to authenticate as any known username. Exploitation has been confirmed in the wild since May 7, 2026, a full month before patches existed, with at least one incident tied to a Qilin ransomware affiliate, and the bypass works over both UDP 500 and TCP 443.
⚠️Why It Matters for MSSPs
If you or any of your clients run Check Point Security Gateways with Remote Access VPN enabled and have not applied hotfix sk185033, any attacker who can enumerate a valid username can walk straight through the perimeter with a forged identity and no valid credentials. For your own stack, if you use Check Point as your own edge or client-facing VPN, you are the target and a compromised gateway means an attacker is inside the same network segment where your RMM and PSA tools live. For your clients, the Qilin ransomware connection means this is not a theoretical risk and if you have not already told them to patch, you are behind the attackers by a month.
Recommended Action
Pull a list of every Check Point Security Gateway in your client inventory and your own environment right now, confirm whether sk185033 has been applied, and send a direct written advisory to every client running an affected Gaia version today before end of business.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.