🔴
CISA KEV Alert — Active Real-World Exploitation Confirmed
This vulnerability is in the CISA Known Exploited Vulnerabilities catalog and is being actively exploited right now.

Check Point Security Gateway Authentication Bypass RCE (CVE-2026-50751) | MSSP Advisory

Critical🔴 KEV ALERTConfirmed
DateJune 8, 2026
CVECVE-2026-50751
Risk Assessment
Client Exposure:High
Briefing Priority:Immediate
Barrier to Entry:Low
📋Executive Summary
CISA has added CVE-2026-50751 to the Known Exploited Vulnerabilities catalog, confirming that attackers are actively bypassing authentication on Check Point Security Gateways through a flaw in IKEv1 key exchange. An unauthenticated remote attacker can establish a full VPN tunnel without a valid password, meaning perimeter controls on affected gateways are effectively nullified. The June 11 deadline is a floor, not a target — exploitation is happening now.
⚠️Why It Matters for MSSPs
If your MSSP runs Check Point Security Gateways as part of your own remote access infrastructure, an attacker can tunnel directly into your management environment and reach every client network you touch from there. Even if you are not a Check Point shop internally, a meaningful portion of your mid-market client base almost certainly is, and your advisory obligation requires you to contact those clients today, not after the patch window closes.
Recommended Action
Audit every Check Point Security Gateway in your own stack and across all client accounts within the next 24 hours and confirm patch status against the vendor advisory. For any unpatched gateway, treat it as actively compromised, restrict IKEv1 negotiation at the firewall policy level as an immediate compensating control, and push the vendor patch the moment it clears your change process. Client-facing communication goes out today.
🔒
Partner content — get access free
The recommended action is included in your white-labeled advisory — ready to send to clients under your name.
Get your first advisory free →
🏷️Threat Category
Vulnerability Disclosure

Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.