CVE-2026-50751
Check Point Security Gateway Improper Authentication Vulnerability
- 대응 우선순위
- 최우선
- CVSS
- 9.3
- EPSS
- 71.1% 백분위 99.3% · 2026.06.27 기준
- CISA KEV
- 등록
- 조치 기한
- 2026.06.11
- 공개일
- 2026.06.08
CISA KEV에 등록된 실제 악용 확인 취약점
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
공급사 Check Point
제품 Security Gateway
영향 버전 R82.10 with Jumbo Hotfix Take 19 or below, R82 with Jumbo Hotfix Take 103 or below, R81.20 with Jumbo Hotfix Take 141 or below, R81.10, R81, and R80.40, R80.20.X, R81.10.X, and R82.00.X, >= r80.40 < r81.20, r81.20, r82, r82.10, >= r80.20.00 < r81.10.17, r81.10.17, >= r80.20.00 < r82.00.10, r82.00.10
수정 버전 r81.20, r81.10.17, r82.00.10
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
조치 기한: 2026.06.11CVSS 벡터 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
CWE CWE-287
KEV 등록일 2026.06.08
랜섬웨어 캠페인 사용 확인됨
CISA 비고 https://blog.checkpoint.com/security/check-point-releases-important-hotfix-for-vulnerabilities-in-deprecated-ikev1-vpn-protocol/ ; https://support.checkpoint.com/results/sk/sk185033?_gl=1*1wqeqhc*_gcl_au*MTI1MzE5MjI2LjE3ODA5MzQ1NTM. ; https://nvd.nist.gov/vuln/detail/CVE-2026-50751
EPSS 데이터 기준일 2026.06.27