VDB

CVE-2026-50752

CVE-2026-50752 PUBLISHED CVSS 7.4 HIGH

Reported by checkpoint · Published June 8, 2026

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.

Risk Scores

CVSS 3.1
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
checkpointQuantum Security GatewayR82.10 with Jumbo Hotfix Take 19 or below, R82 with Jumbo Hotfix Take 103 or below, R81.20 with Jumbo Hotfix Take 141 or below
checkpointSpark FirewallsR80.20.X, R81.10.X, and R82.00.X
checkpointQuantum Security GatewayR81.10, R81, and R80.40, R82.10 with Jumbo Hotfix Take 19 or below, R82 with Jumbo Hotfix Take 103 or below
checkpointSpark FirewallsR80.20.X, R81.10.X, and R82.00.X, R80.20.X, R81.10.X, and R82.00.X, R80.20.X, R81.10.X, and R82.00.X

Timeline

  • Jun 8, 2026 CVE Published
  • Jun 9, 2026 Coalition ESS Score
  • Jun 10, 2026 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›