CyberICT

CVE-2026-50751

Check Point · Published June 8, 2026

CVSS v3.1

CRITICAL
Patch availableGet patch

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Affected Products

  • Gaia OS < r81.20
  • Gaia OS
  • Gaia Embedded < r81.10.17
  • Gaia Embedded

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N