Skip to content
CodeAuditAgent

CVE-2026-50751

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Weakness

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Affected products

  • checkpoint gaia_os
  • checkpoint gaia_embedded
  • checkpoint quantum_spark_1530
  • checkpoint quantum_spark_1550
  • checkpoint quantum_spark_1570
  • checkpoint quantum_spark_1570r
  • checkpoint quantum_spark_1590
  • checkpoint quantum_spark_1595r

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.