sk185033 - CVE-2026-50751 - User Authentication bypass on VPN Remote Access and Mobile Access in deprecated IKEv1 key exchange

CVE-2026-50751 - User Authentication bypass on VPN Remote Access and Mobile Access in deprecated IKEv1 key exchange

Please read this important update from Check Point.

Security Alert:

High

Product

Mobile Access / SSL VPN, Remote Access VPN, Spark Firewall

Version

R80.20.X (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10

OS

Gaia, Gaia Embedded

Last Modified

2026-07-07

Symptoms

Vulnerable Configurations

Versions:

When (all required) :

  1. VPN Remote Access or Mobile Access is enabled
  2. IKEv1 is enabled for remote access
  3. Gateways accept legacy Remote Access clients
  4. Gateways do not demand a machine certificate for connections

Solution

Table of Contents:

How to Identify an Attack

Search your Check Point SmartConsole logs for possible VPN certificate authentication attempts associated with the observed attacker infrastructure and certificate subject names.

  1. Recommended time range

Search at least this period: 2026-05-07 through 2026-06-05 Note - For broader assurance, you may search the last 60 days.

  1. Hunt for attacker IP addresses

In the SmartConsole, go to Logs & Monitor / Logs & Events, and search for events where either the source IP or destination IP matches one of the known attacker IP addresses.

Attacker IP addresses

IOCs observed from May 7 to June 8, 2026

IOCs added on June 9, 2026

IOCs added on June 10, 2026

IOCs added on June 11, 2026

SmartConsole query (src:45.77.149.152 OR dst:45.77.149.152 OR src:209.182.225.136 OR dst:209.182.225.136 OR src:38.60.157.139 OR dst:38.60.157.139 OR src:162.33.177.101 OR dst:162.33.177.101 OR src:45.76.26.42 OR dst:45.76.26.42 OR src:144.208.127.155 OR dst:144.208.127.155 OR src:38.54.88.201 OR dst:38.54.88.201 OR dst:38.54.107.167 OR dst:66.42.99.200 OR dst:45.63.104.106 OR dst:45.61.136.173 OR dst:146.71.81.184 OR dst:208.123.119.167 OR dst:64.176.228.109 OR dst:158.247.195.147 OR dst:144.208.127.134)

  1. Hunt specifically for VPN / IKE activity

After identifying matching logs, you should focus on VPN and IKE-related events, especially Key Install.

Focused Key Install query action:"Key Install" AND (src:45.77.149.152 OR dst:45.77.149.152 OR src:209.182.225.136 OR dst:209.182.225.136 OR src:38.60.157.139 OR dst:38.60.157.139 OR src:162.33.177.101 OR dst:162.33.177.101 OR src:45.76.26.42 OR dst:45.76.26.42 OR src:144.208.127.155 OR dst:144.208.127.155 OR src:38.54.88.201 OR dst:38.54.88.201 OR dst:38.54.107.167 OR dst:66.42.99.200 OR dst:45.63.104.106 OR dst:45.61.136.173 OR dst:146.71.81.184 OR dst:208.123.119.167 OR dst:64.176.228.109 OR dst:158.247.195.147 OR dst:144.208.127.134)

Quick Mode / IKE query

Use this to find IKE events where the log record contains Quick: action:"Key Install" AND Quick AND (src:45.77.149.152 OR dst:45.77.149.152 OR src:209.182.225.136 OR dst:209.182.225.136 OR src:38.60.157.139 OR dst:38.60.157.139 OR src:162.33.177.101 OR dst:162.33.177.101 OR src:45.76.26.42 OR dst:45.76.26.42 OR src:144.208.127.155 OR dst:144.208.127.155 OR src:38.54.88.201 OR dst:38.54.88.201 OR dst:38.54.107.167 OR dst:66.42.99.200 OR dst:45.63.104.106 OR dst:45.61.136.173 OR dst:146.71.81.184 OR dst:208.123.119.167 OR dst:64.176.228.109 OR dst:158.247.195.147 OR dst:144.208.127.134)

A successful exploit requires a Quick mode key install.

  1. IPS signature triggered To improve visibility into attack attempts and scanning activity, we recommend enabling the IPS protection IKEv1 Remote Access Authentication Bypass PoC Exploit (CVE-2026-50751). This protection is not a remediation. You should use it in addition to installing the hotfix or applying the recommended mitigation steps.

For more incident investigation steps, refer to the IKEv1 Certificate Authentication Bypass Hunting Guide.

Mitigation Options

Implement one of these mitigation actions:

Option 1 - Remove support for legacy Remote Access client connections

  1. In SmartConsole, open the Security Gateway object properties.

  2. Go to VPN Clients > Authentication.

  3. Clear the Allow older clients to connect to this gateway checkbox:

  4. In the Multiple Authentication Clients Settings section, define the authentication methods required. See the Mobile Access Administration Guide for details.

  5. If Mobile Access is enabled: In the Security Gateway object properties, go to Mobile Access > Authentication and clear the Allow older clients to connect to this gateway checkbox:

  6. Click OK and Install the Security Policy.

Notes:

Option 2 - Configure Global properties for Remote Access VPN Authentication to IKEv2 only

For Security Gateways

  1. In SmartConsole, click menu icon and select Global properties.

  2. Go to Remote Access > VPN Authentication.

  3. In Encryption method, select IKEv2 only checkbox:

  4. Click OK and Install the Security Policy.

For information on IKEv2 support on Remote Access VPN clients, see sk166415.

For locally managed Spark Firewall R82.00.X and R81.10.X with StrongSWAN: Note: Remote Access VPN with IKEv2 is not supported on R81.10.X if you do not use StrongSWAN client.

  1. In Spark WebUI, go to Device > Advanced Setting

  2. In Remote Access VPN - Encryption Method advanced setting, from the drop-down menu, select IKEv2:

  3. Click Save

Option 3 - Set the Machine Certificate Authentication as mandatory

  1. In SmartConsole, open the Security Gateway object properties.

  2. Go to VPN Clients > Authentication.

  3. In the Machine Certificate Authentication section, select Mandatory.

  4. Click OK and Install the Security Policy.

Note: This mitigation option is not relevant for locally managed Spark Firewall.

Recommended step - Install Jumbo Hotfix Accumulator

The fix is included in these Jumbo Hotfix Accumulators:

Version Take #
R82.10 Jumbo Hotfix Accumulator Take 24
R82 Jumbo Hotfix Accumulator Take 107
R81.20 Jumbo Hotfix Accumulator Take 146
R81.10 Jumbo Hotfix Accumulator Take 187

Hotfix for R81.20, R82, and R82.10

Check Point can supply a Hotfix for R81.20, R82, and R82.10. Download the Hotfix relevant to your version:

For Security Gateway / Security Group Member

Hotfix on top Take # Download link
R82.10 Jumbo Hotfix Accumulator Take 19 3 TAR for 3900 appliances
R82.10 Jumbo Hotfix Accumulator Take 6 2 TAR for 3900 appliances
R82 Jumbo Hotfix Accumulator Take 103 2 Download link
R82 Jumbo Hotfix Accumulator Take 91 2 Download link
R82 Jumbo Hotfix Accumulator Take 60 3 Download link
R82 Jumbo Hotfix Accumulator Take 44 1 Download link
R81.20 Jumbo Hotfix Accumulator Take 141 2 Download link
R81.20 Jumbo Hotfix Accumulator Take 127 2 Download link
R81.20 Jumbo Hotfix Accumulator Take 120 2 Download link
R81.20 Jumbo Hotfix Accumulator Take 118 1 Download link
R81.20 Jumbo Hotfix Accumulator Take 113 2 Download link
R81.20 Jumbo Hotfix Accumulator Take 105 1 Download link
R81.20 Jumbo Hotfix Accumulator Take 92 1 Download link

Revision History

Date Description
15 Jun 2026 Added Recommended step
- R82.10 Jumbo Hotfix Accumulator Take 24
- R82 Jumbo Hotfix Accumulator Take 107
- R81.20 Jumbo Hotfix Accumulator Take 146
14 Jun 2026 Added Hotfixes for
- R82 Jumbo Hotfix Accumulator Take 60
- R82 Jumbo Hotfix Accumulator Take 44
13 Jun 2026 - Added more Attacker IP addresses
- Added "How to Identify an Attack" > "(4) IPS signature triggered" section
11 Jun 2026 Added Recommended step - R81.10 Jumbo Hotfix Accumulator Take 187.

Article Properties

Access Level: General

Severity: High

Status: Approved

Date Created: 2026-06-04

Last Modified: 2026-07-07