CISA Warns of Check Point Security Gateway CVE-2024-24919 Exploited
Key Takeaways CISA has issued a critical warning regarding active exploitation of CVE-2026-50751 in Check Point Security Gateway products. This vulnerability allows unauthenticated attackers to...
Key Takeaways
- CISA has issued a critical warning regarding active exploitation of CVE-2026-50751 in Check Point Security Gateway products.
- This vulnerability allows unauthenticated attackers to bypass VPN authentication and gain unauthorized network access.
- The flaw specifically impacts gateways configured with the deprecated IKEv1 protocol for remote access VPN.
- Exploitation is confirmed in ongoing ransomware campaigns, posing a severe threat to enterprise networks.
- A hotfix is available, and organizations are urged to apply it immediately and disable IKEv1 where possible.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert concerning a critical security flaw in Check Point Security Gateway products, identified as CVE-2026-50751. This vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, signaling active exploitation by threat actors, particularly in ransomware operations.
Table Of Content
This severe vulnerability permits unauthenticated remote attackers to bypass established user authentication protocols, thereby enabling them to establish unauthorized VPN connections. Such access presents a profound risk to the integrity and security of enterprise networks globally.
Understanding CVE-2026-50751
Tracked as CVE-2026-50751, this flaw is categorized as an improper authentication vulnerability (CWE-287). It specifically affects the Internet Key Exchange version 1 (IKEv1) protocol within Check Point Security Gateway implementations. The vulnerability allows an attacker without valid credentials to circumvent standard authentication mechanisms and establish a remote access VPN tunnel, completely bypassing the requirement for a user password.
IKEv1, a protocol used to negotiate and set up IPsec VPN sessions, is now considered deprecated. Despite its legacy status, numerous organizations continue to utilize IKEv1 in their production environments. This continued use creates a significant security exposure that malicious actors are now actively leveraging.
Successful exploitation of this vulnerability provides attackers with a direct entry point into the target network perimeter. This effectively neutralizes the security gateway’s intended function as a protective boundary, granting attackers an immediate foothold within the internal network.
Active Exploitation and Ransomware Campaigns
CISA officially added CVE-2026-50751 to its KEV catalog on June 8, 2026, mandating that all federal civilian executive branch (FCEB) agencies remediate the vulnerability by June 11, 2026. Crucially, CISA has confirmed that this vulnerability is actively being used in ransomware campaigns, underscoring the critical need for all organizations, not just federal entities, to take immediate action.
The ability to silently authenticate into a VPN without requiring credentials makes this flaw an extremely dangerous initial access vector. Ransomware operators frequently target VPN gateways as primary entry points, which facilitates lateral movement, data exfiltration, and the eventual deployment of malicious payloads across compromised networks.
The vulnerability specifically impacts Check Point Security Gateway products that have the IKEv1 protocol enabled for remote access VPN. Organizations utilizing these gateways with IKEv1 are at direct risk. An attacker exploiting this flaw could:
- Completely bypass multi-factor and password-based authentication.
- Establish persistent VPN access to internal network segments.
- Move laterally to high-value targets, including domain controllers and data repositories.
- Deploy ransomware or exfiltrate sensitive data without triggering standard authentication alerts.
What You Should Do
Check Point has released an official hotfix to address this vulnerability within deprecated IKEv1 VPN protocol implementations. CISA strongly advises organizations to take the following immediate steps:
- Apply vendor-issued mitigations as outlined in Check Point’s security advisory and support article SK185033.
- Adhere to BOD 22-01 guidance for cloud-based deployments of affected products.
- Discontinue the use of the product if vendor mitigations cannot be applied promptly.
- Disable IKEv1 in all instances where it is not explicitly required and migrate to IKEv2, which is the modern, supported alternative.
Additionally, organizations should conduct thorough audits of VPN authentication logs for any anomalous connection attempts that lack corresponding valid credential events. Such anomalies could indicate prior exploitation of this vulnerability. This disclosure highlights the ongoing risks associated with supporting legacy protocols in enterprise security products. VPN gateways remain high-value targets because their compromise grants attackers what appears to be authenticated network access. Security teams must treat this patch as a top priority and ensure hotfix deployment across all gateway instances before CISA’s mandated deadline.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.