Latest Check Point vulnerability: CVE-2026-50751 #

Check Point disclosed that certain versions of their VPN products utilize the deprecated IKE protocol version 1 (IKEv1) that are affected by an authentication logic flow vulnerability. Remote unauthenticated attackers can utilize this vulnerability to bypass the authentication validation without credentials in order to gain access to secure networks. This vulnerability has been designated CVE-2026-50751 and has been rated critical with a CVSS score of 9.3.

    The following versions are affected:

      • Security Gateways:
        • R82.10 Jumbo Hotfix Take 19 or below
        • R82 Jumbo Hotfix Take 103 or below
        • R81.20 Jumbo Hotfix Take 141 or below
        • R81.10 (End-of-Support (EOS))
        • R81 (End-of-Support (EOS))
        • R80.40 (End-of-Support (EOS))
      • Spark Firewalls: 
        • R80.20.X (End-of-Support (EOS))
        • R82.00.X
        • R81.10.X

        What is Check Point Remote Access and Mobile Access VPN? #

        Check Point Remote Access and Mobile Access VPN provide users access to corporate networks over IPSec.

        What is the impact? #

        Successful exploitation of the vulnerability would allow an attacker to establish an unauthorized VPN connection and gain access to protected networks.

        Are updates or workarounds available? #

        Users are encouraged upgrade affected systems to the following versions:

        Security Gateway, Maestro Orchestrator, and Security Group

        • R82.10 Jumbo Hotfix Accumulator Take 19 (Take #3)
        • R82.10 Jumbo Hotfix Accumulator Take 6 (Take #2)
        • R82 Jumbo Hotfix Accumulator Take 103 (Take #2)
        • R82 Jumbo Hotfix Accumulator Take 91 (Take #2)
        • R81.20 Jumbo Hotfix Accumulator Take 141 (Take #2)
        • R81.20 Jumbo Hotfix Accumulator Take 127 (Take #2)
        • R81.20 Jumbo Hotfix Accumulator Take 120 (Take #2)
        • R81.20 Jumbo Hotfix Accumulator Take 113 (Take #2)

        Spark Firewall Appliances

        • R82.00.10 Build 998002216

        For End-of-Support products Check Point has provided multiple mitigation options.

          How to find potentially vulnerable systems with runZero #

          From the Service inventory, use the following query to locate potentially impacted assets:

          hw:="Check Point%" AND protocol:ike AND ike.version:="1.0"

          May 2024: CVE-2024-24919 #

          On May 28, 2024, Check Point disclosed a serious vulnerability in Check Point Security Gateway Devices with certain remote access software blades (security modules) enabled. Per their guidance, devices are impacted if one of the following conditions are met:

          • The IPsec VPN Blade is enabled, but ONLY when included in the Remote Access VPN community.
          • The Mobile Access Software Blade is enabled.

          The issue, identified as CVE-2024-24919, allows reading arbitrary files on the targeted appliance by unauthenticated remote attackers. This vulnerability could be leveraged to read sensitive files such as those containing password hashes, certificates, and ssh keys.

          This vulnerability has a CVSS score of 8.6 out of 10, indicating that this is a high risk vulnerability. According to their disclosure and information provided by CISA this vulnerability is being actively exploited. A report from mnemonic.io states that they have observed attacks at least as far back as April 30, 2024.

          What is the impact? #

          Upon successful exploitation of the vulnerability, unauthenticated remote attackers could access password hashes for local users. If the hashes are cracked the attacker may be able to log into these user accounts if secondary controls, such as MFA, are not enforced. This includes service accounts that may be used to access Active Directory or other services. Attackers could leverage this information to move across a target's network. 

          Are updates or workarounds available? #

          Check Point has released a software updates to address this vulnerability. They also provide guidance for other measures that should be taken after the vulnerability has been addressed. These can be found in their advisory.

          How do I find potentially vulnerable Check Point devices with runZero? #

          From the Asset Inventory, use the following query to locate assets that may be running the vulnerable operating system in your network:

          hardware:"Check Point" AND (_service.last.http.body:"Check Point Mobile" OR _service.http.body:"Check Point Mobile" OR udp_port:500)

          Written by Tom Sellers

          Tom Sellers is a Principal Research Engineer at runZero. In his 25 years in IT and Security he has built, broken, and defended networks for companies in the finance, service provider, and security software industries. He has built and operated Internet scale scanning and honeypot projects. He is credited on many patents for network deception techonology. A strong believer in Open Source he has contributed to projects such as Nmap, Metasploit, and Recog.

          More about Tom Sellers

          Written by Cale Black

          More about Cale Black
          Subscribe Now

          Get the latest news and expert insights delivered in your inbox.

          Welcome to the club! Your subscription to our newsletter is successful.

          Explore more runZero

          Product
          Announcing runZero 4.9: Unmask attack paths and segmentation gaps with advanced topology and deep OT device intelligence
          With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
          Webcasts
          runZero Hour, Ep. 30: Segmentation - stop assuming & start verifying with runZero 4.9
          See runZero 4.9 in action! Join HD Moore and Tod Beardsley to learn how interactive attack path mapping and advanced OT intelligence expose hidden...
          Product Videos
          runZero 4.9: Advanced topology, attack path mapping, & deep OT intelligence
          With runZero 4.9, visualize attacker lateral movement, harden network choke points, gain deep OT telemetry to secure converged environments, and more.
          runZero Perspective
          Dawn of the apex agentic adversary
          When agentic AI can weaponize exploits in seconds, visibility is everything. Stop the predator with runZero’s exposure management for the AI-attack...
          Podcasts
          From two weeks to three days: The KEV deadline debate
          Former CISA insider Todd Beardsley joins Greg to reveal what it takes to land on the KEV catalog and why ultra-short patching deadlines might...
          Solution Briefs
          runZero for NIS2 compliance
          You can’t secure what you can’t see. runZero provides the complete asset visibility and continuous reporting you need to satisfy strict NIS2...
          Webcasts
          Hardening attack surfaces against AI-powered exploits
          Learn to find rogue IoT, multi-homed devices, and hidden attack paths. HD Moore shares a blueprint for total attack surface management in the age...
          Podcasts
          OT asset exposures & mitigations
          Rob King joins the Nexus Podcast to discuss the security risks and exposures introduced by digital transformation to operational technology...

          See Results in Minutes

          See & secure your total attack surface. Even the unknowns & unmanageable.