Skip to main content
QUIETLYTIC
Vulnerability

Check Point Quantum Security Gateway Vulnerability (CVE-2026-50752)

CVE-2026-50752 is a CVSS 7.4 certificate-validation flaw in Check Point VPN gateways, reported exploited by VulnCheck alone.

CVE-2026-50752
Threat Level
HIGH
CVSS
7.4
Status
Active Exploitation
Confidence
Medium
Affected Products
Check Point Quantum Security Gateway

CVE-2026-50752 carries a CVSS 3.1 base score of 7.4 against Check Point’s Quantum Security Gateway. NVD classifies it as CWE-295 (Improper Certificate Validation). VulnCheck’s KEV feed reports the CVE as exploited, dated September 16, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-50752 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description states a weakness exists in the certificate-validation logic of the deprecated IKEv1 key-exchange protocol, which may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. NVD states successful exploitation could allow interception or modification of traffic traversing the affected VPN tunnel. NVD does not specify the exact certificate field or validation step involved beyond that summary; Check Point’s own linked security advisory is the authoritative technical source.

Evidence and confidence

  • Medium confidence — the CVSS 7.4 score, the vector (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N), and the CWE-295 classification, which trace to NVD alone in our current ingestion. The exploitation report traces to VulnCheck KEV alone.
  • Very high exploitation probability — FIRST’s EPSS model scores this CVE at 0.05005, a 91.8th percentile score as of our ingestion — notably high for a VulnCheck-only listing.

No field is in conflict between our two sources. Our source data does not carry a fixed-version field; consult Check Point’s own security advisory directly for patch guidance.

Why this matters

Site-to-site VPN tunnels are typically used to connect trusted networks — branch offices, data centers, partner organizations — under the assumption that traffic crossing them is protected from interception by design. A certificate-validation bypass that lets a man-in-the-middle attacker defeat that protection specifically undermines the security guarantee the VPN tunnel exists to provide, and NVD’s own description names both interception and modification of tunneled traffic as achievable outcomes. The requirement for the attacker to be positioned as a man-in-the-middle (AC:H, high attack complexity) narrows the practical exploitation window, but the near-maximal EPSS percentile suggests meaningful exploitation activity is already occurring despite that constraint.

Frequently Asked Questions

What is CVE-2026-50752? A CVSS 7.4 improper certificate validation vulnerability (CWE-295) in the deprecated IKEv1 key-exchange protocol on Check Point Quantum Security Gateway, allowing a man-in-the-middle attacker to bypass certificate validation on site-to-site VPN connections using certificate-based authentication.

Is CVE-2026-50752 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 16, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.

Do I need to be positioned as a man-in-the-middle to exploit this? Yes. NVD’s description specifies the attacker must be positioned as a man-in-the-middle, reflected in the CVSS vector’s high attack-complexity rating.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

Which version fixes this? Our source data does not carry a specific fixed-version field. Consult Check Point’s own security advisory for patch guidance specific to your Quantum Security Gateway deployment.


Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-50752. Check Point’s own advisory: Check Point Security Advisory sk185035. Exploitation status and the September 16, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools