Check Point Remote Access VPNs are vulnerable to a critical authentication bypass (CVE-2026-50751, CVSS 9.3) within the IKEv1 key exchange process. By sending a crafted 'VPNExtFeatures' Vendor ID payload, an attacker can manipulate the negotiation state to skip certificate signature verification, allowing full network access using only a valid username and the gateway's public ICA organization string.
Exploited In The Wild
4 posts
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) Cyber Centre Daily Advisory Digest — 2026-06-11 (2 advisories) The Canadian Centre for Cyber Security issued a daily digest highlighting two critical security advisories. Notably, Oracle PeopleSoft Enterprise PeopleTools is affected by CVE-2026-35273, a critical vulnerability currently being exploited in the wild, while GitLab has released patches for multiple versions of its Community and Enterprise Editions.
Cyber Centre Daily Advisory Digest — 2026-04-16 (2 advisories) The Canadian Centre for Cyber Security issued advisories for critical vulnerabilities in Drupal core and Nginx UI. Notably, the Nginx UI vulnerability (CVE-2026-33032) is currently being exploited in the wild, requiring immediate patching and monitoring of exposed management interfaces.
CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA has added seven actively exploited vulnerabilities affecting Microsoft, Adobe, and Fortinet products to its Known Exploited Vulnerabilities (KEV) Catalog, urging immediate remediation across all organizations to reduce exposure to cyberattacks.